[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f0uZN97WZG7sURdRqdt-WtWHUzub0ZKFwF_NqsG267F8":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":53,"_status":51},1089,"How are Exchange PowerShell commands formatted in the XML file used for execution?","The XML file uses a `Cmd` attribute for the command name (e.g., `Get-Mailbox`) and structures parameters with nested elements. For one parameter it uses a single property, for two parameters it uses two `Property` elements, and for four parameters it uses four. Parameters are filled programmatically using a template. Example formats are shown in the [article](\u002Fnews\u002Fpenetration-technique-remote-access-to-exchange-powershell), such as `Get-RoleGroupMember \"Organization Management\"` or `Get-Mailbox -Identity administrator`.","\u003Cp>The XML file uses a `Cmd` attribute for the command name (e.g., `Get-Mailbox`) and structures parameters with nested elements. For one parameter it uses a single property, for two parameters it uses two `Property` elements, and for four parameters it uses four. Parameters are filled programmatically using a template. Example formats are shown in the [article](\u002Fnews\u002Fpenetration-technique-remote-access-to-exchange-powershell), such as `Get-RoleGroupMember &quot;Organization Management&quot;` or `Get-Mailbox -Identity administrator`.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-technique-remote-access-to-exchange-powershell\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-are-exchange-powershell-commands-formatted-in-the-xml-file-used-for-executio-1777480499840","XML format, command parameters, Cmd attribute, Get-Mailbox, Get-RoleGroupMember",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},265,"Penetration Technique: Remote Access to Exchange PowerShell","penetration-technique-remote-access-to-exchange-powershell","Guide to Exchange PowerShell remote access penetration technique (fixed in CVE-2022-41040): implementation details, ProxyShell, NTLM auth & Python3 code tweaks for command execution.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>Penetration Technique: Remote Access to Exchange PowerShell\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>0x00 Preface\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Exchange PowerShell is based on PowerShell Remoting, which usually requires accessing port 80 of the Exchange Server from a domain-joined host, with many restrictions. This article introduces an implementation method that does not rely on initiating connections from domain-joined hosts, expanding the scope of application.\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>This method was fixed in CVE-2022–41040. Fix location: RemoveExplicitLogonFromUrlAbsoluteUri(string absoluteUri, string explicitLogonAddress) in C:\\Program Files\\Microsoft\\Exchange Server\\V15\\Bin\\Microsoft.Exchange.HttpProxy.Common.dll, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396808297_0_1e8077e5c0.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>0x01 Introduction\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article will introduce the following content:\u003C\u002Fp>\u003Cp>Implementation Ideas\u003C\u002Fp>\u003Cp>Implementation Details\u003C\u002Fp>\u003Cp>\u003Cstrong>0x02 Implementation Ideas\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In conventional usage, the following issues need to be noted when using Exchange PowerShell:\u003C\u002Fp>\u003Cp>All domain users can connect to Exchange PowerShell\u003C\u002Fp>\u003Cp>Connections need to be initiated from a domain-joined host\u003C\u002Fp>\u003Cp>The connection address needs to use FQDN; IP is not supported\u003C\u002Fp>\u003Cp>Conventional usage cannot initiate connections from outside the domain, but as we know, connections can be initiated from outside the domain via ProxyShell, using SSRF to execute Exchange PowerShell\u003C\u002Fp>\u003Cp>Furthermore, after applying the ProxyShell patch, the SSRF that supports NTLM authentication was not removed, and we can access Exchange Powershell again via NTLM authentication\u003C\u002Fp>\u003Cp>\u003Cstrong>0x03 Implementation Details\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In code implementation, we can add NTLM authentication to pass credentials; example code:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396813170_1_8f5087763c.png\">\u003C\u002Fp>\u003Cp>When executing Exchange Powershell commands, we can choose pypsrp or Flask; for specific details, refer to previous articles: ProxyShell Exploitation Analysis 2 – CVE-2021-34523 and ProxyShell Exploitation Analysis 3 – Adding Users and File Writing\u003C\u002Fp>\u003Cp>Both pypsrp and Flask achieve command execution by establishing a web proxy to filter and modify communication data\u003C\u002Fp>\u003Cp>To increase the code's applicability, another implementation method is chosen here: simulate the normal communication data of Exchange Powershell to achieve command execution\u003C\u002Fp>\u003Cp>Reference code available at: https:\u002F\u002Fgist.github.com\u002Frskvp93\u002F4e353e709c340cb18185f82dbec30e58\u003C\u002Fp>\u003Cp>The code uses Python2 and implements ProxyShell exploitation\u003C\u002Fp>\u003Cp>Based on this code, rewrite it to support Python3, with the function of accessing Exchange Powershell via NTLM authentication to execute commands. The specific details to note are as follows:\u003C\u002Fp>\u003Cp>\u003Cstrong>1. There are differences in string formatting between Python2 and Python3\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Code usable under Python2:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396814950_2_2c87ea7fc4.png\">\u003C\u002Fp>\u003Cp>When using the above code under Python3, it is necessary to convert Str to bytes, and to avoid invisible character parsing issues, the code structure has been redesigned. Code usable under Python3:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396819596_3_88e18f938b.png\">\u003C\u002Fp>\u003Cp>(2)\u003C\u002Fp>\u003Cp>Code usable under Python2:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396822965_4_979e6b3c16.png\">When using the above code in Python3, you need to convert Str to bytes. Example code available for Python3:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396825003_5_c8eaa16cf9.png\">\u003C\u002Fp>\u003Cp>(3)\u003C\u002Fp>\u003Cp>Code available for Python2:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396826696_6_53d0ac7a0f.png\">\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396833065_7_e5c5b1cb01.png\">\u003C\u002Fp>\u003Cp>When using the above code in Python3, you need to convert Str to bytes. To avoid invisible character parsing issues, you cannot use .decode('utf-8') here; instead, use .decode('ISO-8859-1')\u003C\u002Fp>\u003Cp>Example code available for Python3:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396838673_8_f92228b58b.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. XML file format supporting Exchange Powershell commands\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>XML file format example 1:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396840840_9_e4ee5e5a16.png\">\u003C\u002Fp>\u003Cp>The corresponding command to execute is: Get-RoleGroupMember \"Organization Management\"\u003C\u002Fp>\u003Cp>XML file format example 2:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396844848_10_61c81a2b25.png\">\u003C\u002Fp>\u003Cp>The corresponding command to execute is: Get-Mailbox -Identity administrator\u003C\u002Fp>\u003Cp>Through format analysis, the following conclusions can be drawn:\u003C\u002Fp>\u003Cp>\u003Cstrong>(1) The Cmd attribute corresponds to the command name\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396847745_11_32a117109f.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(2) Pay attention to the format of the incoming command parameters\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If only one parameter is passed in, the corresponding format is:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396848485_12_90791f5afc.png\">If 2 parameters are passed in, the corresponding format is:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396848855_13_c66186efba.png\">\u003C\u002Fp>\u003Cp>If 4 parameters are passed in, the corresponding format is:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396849195_14_4d83100200.png\">To this end, we can use the following code to implement parameter filling:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396849615_15_056dab597c.png\">Implementation code for constructing the XML file format:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396851057_16_dd9ba486ec.png\">\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396853936_17_92a8bdc544.png\">\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396857540_18_5f51c1907e.png\">After combining the above details, we can get the final implementation code, and the execution result of the code is as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fuploads\u002Fdocx_image_1769396858766_19_c9befa0e11.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>0x04 Summary\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article introduces the implementation method of remote access to Exchange PowerShell. Its advantage is that it does not rely on initiating connections from hosts within the domain, and this method was fixed in CVE-2022–41040.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>Penetration Technique: Remote Access to Exchange PowerShell\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>0x00 Preface\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Exchange PowerShell is based on PowerShell Remoting, which usually requires accessing port 80 of the Exchange Server from a domain-joined host, with many restrictions. This article introduces an implementation method that does not rely on initiating connections from domain-joined hosts, expanding the scope of application.\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>This method was fixed in CVE-2022–41040. Fix location: RemoveExplicitLogonFromUrlAbsoluteUri(string absoluteUri, string explicitLogonAddress) in C:\\Program Files\\Microsoft\\Exchange Server\\V15\\Bin\\Microsoft.Exchange.HttpProxy.Common.dll, as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396808297_0_1e8077e5c0-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>0x01 Introduction\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article will introduce the following content:\u003C\u002Fp>\u003Cp>Implementation Ideas\u003C\u002Fp>\u003Cp>Implementation Details\u003C\u002Fp>\u003Cp>\u003Cstrong>0x02 Implementation Ideas\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In conventional usage, the following issues need to be noted when using Exchange PowerShell:\u003C\u002Fp>\u003Cp>All domain users can connect to Exchange PowerShell\u003C\u002Fp>\u003Cp>Connections need to be initiated from a domain-joined host\u003C\u002Fp>\u003Cp>The connection address needs to use FQDN; IP is not supported\u003C\u002Fp>\u003Cp>Conventional usage cannot initiate connections from outside the domain, but as we know, connections can be initiated from outside the domain via ProxyShell, using SSRF to execute Exchange PowerShell\u003C\u002Fp>\u003Cp>Furthermore, after applying the ProxyShell patch, the SSRF that supports NTLM authentication was not removed, and we can access Exchange Powershell again via NTLM authentication\u003C\u002Fp>\u003Cp>\u003Cstrong>0x03 Implementation Details\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In code implementation, we can add NTLM authentication to pass credentials; example code:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396813170_1_8f5087763c-1.png\">\u003C\u002Fp>\u003Cp>When executing Exchange Powershell commands, we can choose pypsrp or Flask; for specific details, refer to previous articles: ProxyShell Exploitation Analysis 2 – CVE-2021-34523 and ProxyShell Exploitation Analysis 3 – Adding Users and File Writing\u003C\u002Fp>\u003Cp>Both pypsrp and Flask achieve command execution by establishing a web proxy to filter and modify communication data\u003C\u002Fp>\u003Cp>To increase the code's applicability, another implementation method is chosen here: simulate the normal communication data of Exchange Powershell to achieve command execution\u003C\u002Fp>\u003Cp>Reference code available at: https:\u002F\u002Fgist.github.com\u002Frskvp93\u002F4e353e709c340cb18185f82dbec30e58\u003C\u002Fp>\u003Cp>The code uses Python2 and implements ProxyShell exploitation\u003C\u002Fp>\u003Cp>Based on this code, rewrite it to support Python3, with the function of accessing Exchange Powershell via NTLM authentication to execute commands. The specific details to note are as follows:\u003C\u002Fp>\u003Cp>\u003Cstrong>1. There are differences in string formatting between Python2 and Python3\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Code usable under Python2:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396814950_2_2c87ea7fc4-1.png\">\u003C\u002Fp>\u003Cp>When using the above code under Python3, it is necessary to convert Str to bytes, and to avoid invisible character parsing issues, the code structure has been redesigned. Code usable under Python3:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396819596_3_88e18f938b-1.png\">\u003C\u002Fp>\u003Cp>(2)\u003C\u002Fp>\u003Cp>Code usable under Python2:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396822965_4_979e6b3c16-1.png\">When using the above code in Python3, you need to convert Str to bytes. Example code available for Python3:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396825003_5_c8eaa16cf9-1.png\">\u003C\u002Fp>\u003Cp>(3)\u003C\u002Fp>\u003Cp>Code available for Python2:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396826696_6_53d0ac7a0f-1.png\">\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396833065_7_e5c5b1cb01-1.png\">\u003C\u002Fp>\u003Cp>When using the above code in Python3, you need to convert Str to bytes. To avoid invisible character parsing issues, you cannot use .decode('utf-8') here; instead, use .decode('ISO-8859-1')\u003C\u002Fp>\u003Cp>Example code available for Python3:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396838673_8_f92228b58b-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. XML file format supporting Exchange Powershell commands\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>XML file format example 1:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396840840_9_e4ee5e5a16-1.png\">\u003C\u002Fp>\u003Cp>The corresponding command to execute is: Get-RoleGroupMember \"Organization Management\"\u003C\u002Fp>\u003Cp>XML file format example 2:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396844848_10_61c81a2b25-1.png\">\u003C\u002Fp>\u003Cp>The corresponding command to execute is: Get-Mailbox -Identity administrator\u003C\u002Fp>\u003Cp>Through format analysis, the following conclusions can be drawn:\u003C\u002Fp>\u003Cp>\u003Cstrong>(1) The Cmd attribute corresponds to the command name\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396847745_11_32a117109f-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(2) Pay attention to the format of the incoming command parameters\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If only one parameter is passed in, the corresponding format is:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396848485_12_90791f5afc-1.png\">If 2 parameters are passed in, the corresponding format is:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396848855_13_c66186efba-1.png\">\u003C\u002Fp>\u003Cp>If 4 parameters are passed in, the corresponding format is:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396849195_14_4d83100200-1.png\">To this end, we can use the following code to implement parameter filling:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396849615_15_056dab597c-1.png\">Implementation code for constructing the XML file format:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396851057_16_dd9ba486ec-1.png\">\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396853936_17_92a8bdc544-1.png\">\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396857540_18_5f51c1907e-1.png\">After combining the above details, we can get the final implementation code, and the execution result of the code is as shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——远程访问Exchange Powershell\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769396858766_19_c9befa0e11-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>0x04 Summary\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This article introduces the implementation method of remote access to Exchange PowerShell. Its advantage is that it does not rely on initiating connections from hosts within the domain, and this method was fixed in CVE-2022–41040.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",236,"Onedaysec",4,"published","2026-02-02T07:25:19.984Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Exchange PowerShell Remote Access Technique (CVE-2022-41040)","Exchange PowerShell,remote access,penetration technique,CVE-2022-41040,ProxyShell,NTLM authentication,Python3,SSRF,command execution,Exchange Server",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46,47],1090,1088,1087,1086,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.731Z","2026-07-23T16:02:31.197Z","draft","2026-07-23T16:16:35.813Z","2026-07-23T16:16:35.812Z"]