COLLABORATION PRO
  • Home
  • Exchange 2019
  • Exchange 2016
  • Exchange 2013
  • Exchange 2010
  • Exchange Online
  • Azure
  • Other Articles
  • Windows
  • Contact
  • About
Select Page
Exchange 2019:- ProxyNotShell Exploit

Exchange 2019:- ProxyNotShell Exploit

by edward | Nov 29, 2023 | Exchange 2016, Exchange 2013, Exchange 2019, Kali Linux, ProxyNotShell

In two of my previous blog posts, we looked at exploiting unpatched/vulnerable Exchange servers with “ProxyLogon” and “ProxyShell”. As the exploit lists keep growing, we will look at the “ProxyNotShell” exploit. One of my many...
Exchange 2019:- ProxyNotShell Exploit

Exchange 2019:- ProxyShell Exploit

by edward | Nov 28, 2023 | Exchange 2016, CVE-2021-34473, Exchange 2019, Kali Linux, ProxyShell

In my previous blog post we looked at the Proxy Logon Exploit where several CVE’s could be used to exploit an Exchange Server. In this article we will look at another exploit called “ProxyShell”. The CVE for this vulnerability is...
Exchange 2019:- ProxyNotShell Exploit

Exchange 2019:- ProxyLogon Exploit

by edward | Nov 27, 2023 | Exchange 2016, Exchange 2019, Hafnium, Kali Linux, ProxyLogon

Many of us know the HAFNIUM attacks that took place a little while ago and many Exchange servers were compromised. The sad part is that many Exchange Servers are still unpatched and vulnerable to attack, maybe not to the CVE’s listed below but to others as well....
Exchange 2019:- ProxyNotShell Exploit

Exchange 2019:- Using IISCrypto 3.3 with Exchange 2019 CU13

by edward | Nov 26, 2023 | Exchange 2019, IISCrypto 3.3

A few years back I wrote a blog post for Exchange 2016 where we used IISCrypto to remove Protocols, Ciphers, Hashes, Key Exchanges etc. that posed a security risk externally if the servers were published to the internet however upon running a newer release it seemed...
Exchange 2019:- ProxyNotShell Exploit

Exchange 2019:- Brute forcing OWA to gain access to user accounts

by edward | Nov 22, 2023 | Exchange 2016, Active Directory, BurpSuite, Exchange 2013, Exchange 2019, Kali Linux

We all know that end users hate complex passwords and having to change passwords often leads them to use the same password but add a number or character at the end of it. Password complexity is just one of the problems. The next problem is information disclosure such...
Exchange 2019:- ProxyNotShell Exploit

Information disclosure with NTLM Authentication in Exchange Server

by edward | Nov 21, 2023 | Exchange 2016, Exchange 2019, NMAP, NMAP Scripting Engine, NSE

Performing some tests against my lab Exchange servers, I noticed that Shodan.io revealed information. Take note that attackers also use Shodan.io when enumerating targets. After digging further with NMAP and some scripts, it became more apparent that internal...
« Older Entries
Next Entries »
Copyright © 2024 COLLABORATION PRO