[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3tZ4di_rEEMt-69kAeboC6pMNZn3ygOiPMWl2GmIopg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":50,"createdAt":50,"_status":49},477,"How did the article fix the bug related to the Domain parameter for NTLM authentication?","The original ewsManage.py required specifying the Domain parameter (e.g., test.com\\administrator required Domain=test.com). However, if the user was only an administrator without a domain prefix, the Domain parameter could not be set. The fix adds parameter validation: if Domain is NULL, the NTLM Type1 message is generated without the Domain parameter, allowing flexible login for both domain and non-domain users.","\u003Cp>The original ewsManage.py required specifying the Domain parameter (e.g., test.com\\administrator required Domain=test.com). However, if the user was only an administrator without a domain prefix, the Domain parameter could not be set. The fix adds parameter validation: if Domain is NULL, the NTLM Type1 message is generated without the Domain parameter, allowing flexible login for both domain and non-domain users.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fexchange-web-service-ews-development-guide-4-auto-downloader\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-did-the-article-fix-the-bug-related-to-the-domain-parameter-for-ntlm-authent-1777483545372","NTLM authentication, Domain bug, parameter validation, ewsManage.py",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":46,"updatedAt":47,"createdAt":48,"_status":49},119,"Exchange Web Service (EWS) Development Guide 4 – Auto Downloader","exchange-web-service-ews-development-guide-4-auto-downloader","Learn to automate email and attachment downloads with EWS using SOAP XML. Includes keyword\u002Fdate search, NTLM auth, and open-source Python code.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In my previous articles \"Exchange Web Service (EWS) Development Guide\" and \"Exchange Web Service (EWS) Development Guide 2 – SOAP XML Message\", I detailed how to access Exchange resources using hash via SOAP XML messages.\u003C\u002Fp>\u003Cp>Because it is a relatively low-level communication protocol, implementing functionality can be cumbersome. For example, to download email attachments, the following steps must be completed sequentially:\u003C\u002Fp>\u003Cul>\u003Cli>Read folder information to obtain the ItemId and ChangeKey corresponding to the email.\u003C\u002Fli>\u003Cli>Read email information to obtain the ItemId of the attachment.\u003C\u002Fli>\u003Cli>Use the attachment's ItemId to obtain the AttachmentId for each attachment.\u003C\u002Fli>\u003Cli>Download the email content using the AttachmentId and decode the Base64 content to get the actual data.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>To fully automate the process of downloading emails and extracting attachments, the original ewsManage.py requires some modifications.\u003C\u002Fp>\u003Cp>Therefore, this article will introduce the implementation details for automating email downloads and attachment extraction, with the open-source code ewsManage_Downloader.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Design Approach\u003C\u002Fli>\u003Cli>Development Details\u003C\u002Fli>\u003Cli>Open Source Code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Design Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>ewsManage_Downloader must meet the following requirements:\u003C\u002Fp>\u003Cul>\u003Cli>Support login with plaintext and NTLM Hash\u003C\u002Fli>\u003Cli>Support keyword search\u003C\u002Fli>\u003Cli>Support date-based search\u003C\u002Fli>\u003Cli>Allow specifying the download quantity during download\u003C\u002Fli>\u003Cli>Capable of automatically downloading emails and extracting attachments\u003C\u002Fli>\u003C\u002Ful>\u003Cp>During communication, each SOAP XML message request requires full NTLM authentication, preventing the use of session mechanisms to simplify the login process\u003C\u002Fp>\u003Cp>Therefore, the original ewsManage.py code structure needs to be redesigned to reduce code redundancy.\u003C\u002Fp>\u003Ch2>0x03 Development Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Fix the bug related to the Domain parameter for login users\u003C\u002Fh3>\u003Cp>The original ewsManage.py required specifying the Domain of the logged-in user as a parameter.\u003C\u002Fp>\u003Cp>For example, if the logged-in user is test.com\\administrator, the Domain parameter needs to be set to test.com.\u003C\u002Fp>\u003Cp>However, if the logged-in user is administrator, then the Domain parameter cannot be specified.\u003C\u002Fp>\u003Cp>This is an aspect I previously overlooked when using NTLM authentication. The solution is as follows:\u003C\u002Fp>\u003Cp>Add parameter validation: if the Domain parameter is NULL, then do not specify the Domain parameter during NTLM authentication.\u003C\u002Fp>\u003Cp>Code example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>    if domain == \"NULL\":\u003Cbr>        ntlm_nego = ntlm.getNTLMSSPType1(host)\u003Cbr>    else:    \u003Cbr>        ntlm_nego = ntlm.getNTLMSSPType1(host, domain)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Support keyword search\u003C\u002Fh3>\u003Cp>SOAP format to send:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>?xml version=\"1.0\" encoding=\"utf-8\"?&gt;\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:finditem traversal=\"Shallow\">\u003Cbr>      \u003Cm:itemshape>\u003Cbr>        \u003Ct:baseshape>AllProperties\u003C\u002Ft:baseshape>\u003Cbr>      \u003C\u002Fm:itemshape>\u003Cbr>      \u003Cm:parentfolderids>\u003Cbr>        \u003Ct:distinguishedfolderid id=\"{folderpath}\">\u003Cbr>        \u003C\u002Ft:distinguishedfolderid>\u003Cbr>      \u003C\u002Fm:parentfolderids>\u003Cbr>      \u003Cm:querystring>{querystring}\u003C\u002Fm:querystring>\u003Cbr>    \u003C\u002Fm:finditem>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Where {querystring} is the search keyword, the returned results include the ItemId and ChangeKey of emails containing the specified keyword.\u003C\u002Fp>\u003Ch3>3. Supports date-based search\u003C\u002Fh3>\u003Cp>The SOAP format sent is the same as above, with the difference being the {querystring}.\u003C\u002Fp>\u003Cp>Reference 1:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Flwef\u002F-search-2x-wds-aqsreference?redirectedfrom=MSDN\u003C\u002Fp>\u003Cp>The date format in Reference 1 is MM\u002FDD\u002FYY, as shown in the example below:\u003C\u002Fp>\u003Cp>The format corresponding to March 1, 2021 is 03\u002F01\u002F21\u003C\u002Fp>\u003Cp>However, based on actual testing, the syntax for dates in {querystring} cannot follow the format in Reference 1.\u003C\u002Fp>\u003Cp>Reference 2:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Foffice\u002Flearn-to-narrow-your-search-criteria-for-better-searches-in-outlook-d824d1e9-a255-4c8a-8553-276fb895a8da?ocmsassetid=ha010238831&amp;correlationid=bf4cdcf9-abb8-4d43-930e-d0909de76728&amp;ui=en-us&amp;rs=en-us&amp;ad=us\u003C\u002Fp>\u003Cp>The date format in Reference 2 is Year\u002FMonth\u002FDay, as shown in the example below:\u003C\u002Fp>\u003Cp>The format corresponding to March 1, 2021 is 2021\u002F3\u002F1\u003C\u002Fp>\u003Cp>Regarding the date format, the correct syntax follows Reference 2.\u003C\u002Fp>\u003Cp>In summary, the parameters for filtering emails sent between January 1, 2021, and December 30, 2021, are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sent:&gt;=2021\u002F1\u002F1 AND sent:&lt;=2021\u002F12\u002F30\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Filter parameters with receipt time from January 1, 2021 to December 30, 2021 as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>received:&gt;=2021\u002F1\u002F1 AND received:&lt;=2021\u002F12\u002F30\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Support length search\u003C\u002Fh3>\u003Cp>Normally, filter parameters with length less than 2000 as: size:&lt;2000\u003C\u002Fp>\u003Cp>But XML format escaping needs to be considered, the actual parameter content is: size:&lt;2000\u003C\u002Fp>\u003Ch2>0x04 Open Source Code\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Complete code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open source project\u003C\u002Fp>\u003Cp>Supports login with plaintext and NTLM Hash, the code supports the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>download, download emails and extract attachments, can specify mailbox folder and download quantity\u003C\u002Fli>\u003Cli>findallpeople, export contact list\u003C\u002Fli>\u003Cli>search, email search and download, supports syntax for keywords, time, length, etc.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>When downloading emails, the email username is used as the parent folder, different operations create different subfolders. When creating subfolders using the search function, to avoid special characters (e.g., character &gt;) that cannot be used as folder names, special characters are removed here\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article details the development of automated email downloading and attachment extraction, featuring the open-source code ewsManage_Downloader.py, which implements access to Exchange resources using hash.\u003C\u002Fp>\u003Cp>Due to the use of lower-level communication protocols, the functional implementation is relatively cumbersome, but it aids in understanding communication protocol principles and vulnerability exploitation.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",4,"published","2026-02-02T07:51:00.067Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"EWS Auto Downloader: Automate Email & Attachment Downloads","Exchange Web Service, EWS development, email automation, attachment download, SOAP XML, NTLM authentication, keyword search, date search, Python script",false,[],{"docs":41,"hasNextPage":38},[42,43,44,4,45],480,479,478,476,{"title":30,"description":30,"image":30},"2026-07-24T02:07:23.753Z","2026-07-23T16:01:38.124Z","draft","2026-07-23T16:12:36.741Z"]