0:00
/
0:00
Transcript

Tuesday TOOLSday: abusing Exchange

Enumerating users and spraying creds!

Warning: I lost my screen share for part of this presentation, but get it back about 9:30 :-)

Hey friends. For this week’s Tuesday TOOLSday we used this extension from GOAD to build an exchange server and then spent some time enumerating valid users (based on page response time) and spraying credentials to hijack a mailbox! Fun stuff. Enjoy.

-Brian

Get more from Brian Johnson in the Substack app
Available for iOS and Android

Discussion about this video

User's avatar