MS Exchange
Outlook Web Access
Authentication Request
Kerberos Process
Response Time
Enum spray endpoints
./msmailprobe identify -t site.comGet Realm
$ ~ curl -Isk -X POST -H 'Authorization: NTLM TlRMTVNTUAABAAAAB4IIogAAAAAAAAAAAAAAAAAAAAAKANc6AAAADw==' -H 'Content-Length: 0' https://autodiscover.exmaple.com/ews
$ ~ echo 'TlRMTVNTUAACAAAADAAMAD...' | python2 ./ntlmdecoder.py$ ~ curl -Isk https://autodiscover.exmaple.com/microsoft-server-activesync/healthcheck.htmPostexploit
Username generator
Links
Last updated