[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fzxP-241TzCWFzqhCLyl-rTeNHn050GH99iKsE-YTM8k":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},364,"How does ewsManage.py support accessing Exchange resources using an NTLM hash instead of a plaintext password?","ewsManage.py leverages the Impacket library to enable login using either a plaintext password or an NTLM hash. When using hash login, you specify `ntlmhash` as the authentication type and provide the hash value. This technique, often referred to as 'pass-the-hash,' is particularly useful in penetration testing scenarios. For more details on hash-based authentication, see the [Exchange Web Service (EWS) Development Guide 6 – requests_ntlm](\u002Fnews\u002Fexchange-web-service-ews-development-guide-6-requests-ntlm).","\u003Cp>ewsManage.py leverages the Impacket library to enable login using either a plaintext password or an NTLM hash. When using hash login, you specify `ntlmhash` as the authentication type and provide the hash value. This technique, often referred to as &#39;pass-the-hash,&#39; is particularly useful in penetration testing scenarios. For more details on hash-based authentication, see the [Exchange Web Service (EWS) Development Guide 6 – requests_ntlm](\u002Fnews\u002Fexchange-web-service-ews-development-guide-6-requests-ntlm).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fexchange-web-service-ews-development-guide-2-soap-xml-message\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-ewsmanagepy-support-accessing-exchange-resources-using-an-ntlm-hash-ins-1777484015198","NTLM hash, pass-the-hash, Impacket, ewsManage, hash login",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":20,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},92,"Exchange Web Service (EWS) Development Guide 2 – SOAP XML Message","exchange-web-service-ews-development-guide-2-soap-xml-message","Learn to access Exchange resources using SOAP XML messages with hash authentication. Includes Python code for email and attachment retrieval via EWS.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article \"Exchange Web Service (EWS) Development Guide\", the tool ewsManage was open-sourced, enabling access to Exchange resources.\u003C\u002Fp>\u003Cp>This article will take a step further by utilizing SOAP XML messages to achieve access to Exchange resources using a hash.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Methods for accessing Exchange resources using a hash\u003C\u002Fli>\u003Cli>Usage of SOAP XML messages\u003C\u002Fli>\u003Cli>Open-source Python implementation code\u003C\u002Fli>\u003Cli>Code development details\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods for Accessing Exchange Resources Using a Hash\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article \"Penetration Techniques – Pass the Hash with Exchange Web Service\" introduced the method of logging into EWS using a hash.\u003C\u002Fp>\u003Cp>Based on previous research, this article will introduce methods for accessing Exchange resources after logging into EWS. Therefore, Python will continue to be chosen for program implementation, using EWS SOAP XML messages to access Exchange resources.\u003C\u002Fp>\u003Cp>For the format of EWS SOAP XML messages, there are two methods for reference:\u003C\u002Fp>\u003Cp>1. Search for information\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fexchange-web-services\u002Fget-started-with-ews-client-applications\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fews-xml-elements-in-exchange\u003C\u002Fp>\u003Cp>2. Packet capture analysis\u003C\u002Fp>\u003Cp>Configure Wireshark to capture plaintext communication data on the Exchange Server\u003C\u002Fp>\u003Cp>Use ewsManage to access Exchange resources\u003C\u002Fp>\u003Cp>Capture communication data to obtain the EWS SOAP XML message format corresponding to different operations, as shown in the example below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018734621_0_73173d5c01.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Using SOAP XML messages\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Compared to EWS Managed API, SOAP XML messages are more low-level and require consideration of more details.\u003C\u002Fp>\u003Ch3>1. View the number of emails in the inbox\u003C\u002Fh3>\u003Cp>XML format to send:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" \u003Cbr=\"\">               xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" \u003Cbr>               xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" \u003Cbr>               xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\"&gt;\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getfolder>\u003Cbr>      \u003Cm:foldershape>\u003Cbr>        \u003Ct:baseshape>Default\u003C\u002Ft:baseshape>\u003Cbr>      \u003C\u002Fm:foldershape>\u003Cbr>      \u003Cm:folderids>\u003Cbr>        \u003Ct:distinguishedfolderid id=\"inbox\">\u003Cbr>      \u003C\u002Ft:distinguishedfolderid>\u003C\u002Fm:folderids>\u003Cbr>    \u003C\u002Fm:getfolder>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Return content format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cs:envelope xmlns:s=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>\u003Cs:header>\u003Cbr>\u003Ch:serverversioninfo xmlns:h=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:xsd=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema\" xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" majorversion=\"15\" minorversion=\"0\" majorbuildnumber=\"847\" minorbuildnumber=\"31\">\u003Cbr>\u003C\u002Fh:serverversioninfo>\u003C\u002Fs:header>\u003Cbr>\u003Cs:body xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:xsd=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema\">\u003Cbr>\u003Cm:getfolderresponse xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\">\u003Cbr>\u003Cm:responsemessages>\u003Cbr>\u003Cm:getfolderresponsemessage responseclass=\"Success\">\u003Cbr>\u003Cm:responsecode>NoError\u003C\u002Fm:responsecode>\u003Cbr>\u003Cm:folders>\u003Cbr>\u003Ct:folder>\u003Cbr>\u003Ct:folderid id=\"AQAOAHRlc3QxQHRlc3QuY29tAC4AAAOeuRYNE6D6Q70cD0Q\u002Fs0RIAQAXa2D52NzfQYSx7xK5j92NAAACAQ0AAAA=\" changekey=\"AQAAABYAAAAXa2D52NzfQYSx7xK5j92NAAAAABK9\">\u003Cbr>\u003Ct:displayname>Inbox\u003C\u002Ft:displayname>\u003Cbr>\u003Ct:totalcount>6\u003C\u002Ft:totalcount>\u003Cbr>\u003Ct:childfoldercount>0\u003C\u002Ft:childfoldercount>\u003Cbr>\u003Ct:unreadcount>4\u003C\u002Ft:unreadcount>\u003Cbr>\u003C\u002Ft:folderid>\u003C\u002Ft:folder>\u003Cbr>\u003C\u002Fm:folders>\u003Cbr>\u003C\u002Fm:getfolderresponsemessage>\u003Cbr>\u003C\u002Fm:responsemessages>\u003Cbr>\u003C\u002Fm:getfolderresponse>\u003Cbr>\u003C\u002Fs:body>\u003Cbr>\u003C\u002Fs:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The response content reveals the total number of emails and unread emails in the inbox.\u003C\u002Fp>\u003Ch3>2. Retrieve inbox email information\u003C\u002Fh3>\u003Cp>XML format to send:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:finditem traversal=\"Shallow\">\u003Cbr>      \u003Cm:itemshape>\u003Cbr>        \u003Ct:baseshape>AllProperties\u003C\u002Ft:baseshape>\u003Cbr>        \u003Ct:bodytype>Text\u003C\u002Ft:bodytype>\u003Cbr>      \u003C\u002Fm:itemshape>\u003Cbr>      \u003Cm:indexedpageitemview maxentriesreturned=\"2147483647\" offset=\"0\" basepoint=\"Beginning\">\u003Cbr>      \u003Cm:parentfolderids>\u003Cbr>        \u003Ct:distinguishedfolderid id=\"inbox\">\u003Cbr>      \u003C\u002Ft:distinguishedfolderid>\u003C\u002Fm:parentfolderids>\u003Cbr>    \u003C\u002Fm:indexedpageitemview>\u003C\u002Fm:finditem>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The returned content can obtain the subject, sender-recipient relationship, and whether attachments are present for all emails in the inbox, but cannot display the body content or attachment names.\u003C\u002Fp>\u003Cp>The returned content can obtain the ItemId and ChangeKey corresponding to each email, thereby allowing access to the email content, attachment names, and Ids.\u003C\u002Fp>\u003Ch3>3. Obtain the specific content of a specified email\u003C\u002Fh3>\u003Cp>XML format sent:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getitem>\u003Cbr>      \u003Cm:itemshape>\u003Cbr>        \u003Ct:baseshape>AllProperties\u003C\u002Ft:baseshape>\u003Cbr>        \u003Ct:bodytype>Text\u003C\u002Ft:bodytype>\u003Cbr>      \u003C\u002Fm:itemshape>\u003Cbr>      \u003Cm:itemids>\u003Cbr>        \u003Ct:itemid id=\"{id}\" changekey=\"{key}\">\u003Cbr>      \u003C\u002Ft:itemid>\u003C\u002Fm:itemids>\u003Cbr>    \u003C\u002Fm:getitem>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Where {id} is the ItemId of the specified email, and {key} is the ChangeKey of the specified email\u003C\u002Fp>\u003Cp>Detailed information of the email, including the body content, can be obtained from the response\u003C\u002Fp>\u003Ch3>4. Get the attachment names of the specified email\u003C\u002Fh3>\u003Cp>XML format to send:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getitem>\u003Cbr>      \u003Cm:itemshape>\u003Cbr>        \u003Ct:baseshape>IdOnly\u003C\u002Ft:baseshape>\u003Cbr>        \u003Ct:additionalproperties>\u003Cbr>          \u003Ct:fielduri fielduri=\"item:Attachments\">\u003Cbr>        \u003C\u002Ft:fielduri>\u003C\u002Ft:additionalproperties>\u003Cbr>      \u003C\u002Fm:itemshape>\u003Cbr>      \u003Cm:itemids>\u003Cbr>        \u003Ct:itemid id=\"{id}\">\u003Cbr>      \u003C\u002Ft:itemid>\u003C\u002Fm:itemids>\u003Cbr>    \u003C\u002Fm:getitem>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>where {id} is the ItemId corresponding to the specified email\u003C\u002Fp>\u003Cp>Return content format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cs:envelope xmlns:s=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>\u003Cs:header>\u003Cbr>\u003Ch:serverversioninfo xmlns:h=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:xsd=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema\" xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" majorversion=\"15\" minorversion=\"0\" majorbuildnumber=\"847\" minorbuildnumber=\"31\" version=\"V2_8\">\u003Cbr>\u003C\u002Fh:serverversioninfo>\u003C\u002Fs:header>\u003Cbr>\u003Cs:body xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:xsd=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema\">\u003Cbr>\u003Cm:getitemresponse xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\">\u003Cbr>\u003Cm:responsemessages>\u003Cbr>\u003Cm:getitemresponsemessage responseclass=\"Success\">\u003Cbr>\u003Cm:responsecode>NoError\u003C\u002Fm:responsecode>\u003Cbr>\u003Cm:items>\u003Cbr>\u003Ct:message>\u003Cbr>\u003Ct:itemid id=\"AAMkADc2OGUyODVmLWY3NjktNDY2MC1iMzllLTM4MThjYzU4OGQ4YgBGAAAAAACeuRYNE6D6Q70cD0Q\u002Fs0RIBwAXa2D52NzfQYSx7xK5j92NAAAAAAENAAAXa2D52NzfQYSx7xK5j92NAAAAAAztAAA=\" changekey=\"CQAAABYAAAAXa2D52NzfQYSx7xK5j92NAAAAAAzk\">\u003Cbr>\u003Ct:attachments>\u003Cbr>\u003Ct:fileattachment>\u003Cbr>\u003Ct:attachmentid id=\"AAMkADc2OGUyODVmLWY3NjktNDY2MC1iMzllLTM4MThjYzU4OGQ4YgBGAAAAAACeuRYNE6D6Q70cD0Q\u002Fs0RIBwAXa2D52NzfQYSx7xK5j92NAAAAAAENAAAXa2D52NzfQYSx7xKj92NAAAAAAztAAABEgAQAJwa7iI1b4ZGoFo6F\u002FTfALM=\">\u003Cbr>\u003Ct:name>1.docx\u003C\u002Ft:name>\u003Cbr>\u003Ct:size>3013\u003C\u002Ft:size>\u003Cbr>\u003Ct:lastmodifiedtime>2020-05-21T01:17:07\u003C\u002Ft:lastmodifiedtime>\u003Cbr>\u003Ct:isinline>false\u003C\u002Ft:isinline>\u003Cbr>\u003Ct:iscontactphoto>false\u003C\u002Ft:iscontactphoto>\u003Cbr>\u003C\u002Ft:attachmentid>\u003C\u002Ft:fileattachment>\u003Cbr>\u003C\u002Ft:attachments>\u003Cbr>\u003Ct:hasattachments>true\u003C\u002Ft:hasattachments>\u003Cbr>\u003C\u002Ft:itemid>\u003C\u002Ft:message>\u003Cbr>\u003C\u002Fm:items>\u003Cbr>\u003C\u002Fm:getitemresponsemessage>\u003Cbr>\u003C\u002Fm:responsemessages>\u003Cbr>\u003C\u002Fm:getitemresponse>\u003Cbr>\u003C\u002Fs:body>\u003Cbr>\u003C\u002Fs:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The attachment name can be obtained from the returned content, but the attachment content cannot be retrieved.\u003C\u002Fp>\u003Cp>The corresponding Id for each attachment can be obtained from the returned content, thereby allowing retrieval of the attachment type and content.\u003C\u002Fp>\u003Ch3>5. Obtain the content of the specified attachment\u003C\u002Fh3>\u003Cp>XML format to be sent:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getattachment>\u003Cbr>      \u003Cm:attachmentids>\u003Cbr>        \u003Ct:attachmentid id=\"{id}\">\u003Cbr>      \u003C\u002Ft:attachmentid>\u003C\u002Fm:attachmentids>\u003Cbr>    \u003C\u002Fm:getattachment>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>where {id} is the Id corresponding to the specified attachment\u003C\u002Fp>\u003Cp>Return content format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cs:envelope xmlns:s=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>\u003Cs:header>\u003Cbr>\u003Ch:serverversioninfo xmlns:h=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:xsd=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema\" xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" majorversion=\"15\" minorversion=\"0\" majorbuildnumber=\"847\" minorbuildnumber=\"31\" version=\"V2_8\">\u003Cbr>\u003C\u002Fh:serverversioninfo>\u003C\u002Fs:header>\u003Cbr>\u003Cs:body xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:xsd=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema\">\u003Cbr>\u003Cm:getattachmentresponse xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\">\u003Cbr>\u003Cm:responsemessages>\u003Cbr>\u003Cm:getattachmentresponsemessage responseclass=\"Success\">\u003Cbr>\u003Cm:responsecode>NoError\u003C\u002Fm:responsecode>\u003Cbr>\u003Cm:attachments>\u003Cbr>\u003Ct:fileattachment>\u003Cbr>\u003Ct:attachmentid id=\"AAMkADc2OGUyODVmLWY3NjktNDY2MC1iMzllLTM4MThjYzU4OGQ4YgBGAAAAAACeuRYNE6D6Q70cD0Q\u002Fs0RIBwAXa2D52NzfQYSx7xK5j92NAAAAAAENAAAXa2D52NzfQYSx7xK5j92NAAAAAAzvAAABEgAQAK2JBdCt\u002FlxColLkCuqo5hw=\">\u003Cbr>\u003Ct:name>1.txt\u003C\u002Ft:name>\u003Cbr>\u003Ct:contenttype>text\u002Fplain\u003C\u002Ft:contenttype>\u003Cbr>\u003Ct:content>{xxxxxxx}\u003C\u002Ft:content>\u003Cbr>\u003C\u002Ft:attachmentid>\u003C\u002Ft:fileattachment>\u003Cbr>\u003C\u002Fm:attachments>\u003Cbr>\u003C\u002Fm:getattachmentresponsemessage>\u003Cbr>\u003C\u002Fm:responsemessages>\u003Cbr>\u003C\u002Fm:getattachmentresponse>\u003Cbr>\u003C\u002Fs:body>\u003Cbr>\u003C\u002Fs:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The {xxxxxxx} is base64-encoded content, which can be decoded to obtain the attachment's content.\u003C\u002Fp>\u003Cp>Note the attachment type: if it is text, it indicates a text type; otherwise, the attachment must be saved in binary format.\u003C\u002Fp>\u003Ch2>0x04 Open Source Python Implementation Code\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The code has been open-sourced at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Implemented using Python. Impacket must be installed before running the script.\u003C\u002Fp>\u003Cp>Installation method: pip install Impacket\u003C\u002Fp>\u003Cp>Supports login with both plaintext and NTLM hash\u003C\u002Fp>\u003Cp>Functionally, it is largely consistent with ewsManage\u003C\u002Fp>\u003Cp>Supports the following features:\u003C\u002Fp>\u003Cul>\u003Cli>View the number of emails in the inbox\u003C\u002Fli>\u003Cli>View the number of emails in the outbox\u003C\u002Fli>\u003Cli>View inbox email information\u003C\u002Fli>\u003Cli>View outbox email information\u003C\u002Fli>\u003Cli>View detailed information of a specified email\u003C\u002Fli>\u003Cli>View information of a specified attachment\u003C\u002Fli>\u003Cli>Save specified attachments\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Usage example:\u003C\u002Fp>\u003Cp>(1) Check the number of emails in the inbox (using plaintext login)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 getfolderofinbox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) View email information in the inbox (using hash login)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 ntlmhash test.com user1 c5a237b7e9d8e708d8436b6148a25fa1 listmailofinbox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) View specific information of a specified email\u003C\u002Fp>\u003Cp>View email information in the inbox:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 listmailofinbox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Results are saved as listmailofinbox.xml, obtain the corresponding email's ItemId and ChangeKey from the file\u003C\u002Fp>\u003Cp>View specific information of a specified email:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 getmail\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Then input the email's ItemId and ChangeKey\u003C\u002Fp>\u003Cp>Final results are saved as getmail.xml\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018746208_1_ab0f030b1e.jpeg\">\u003C\u002Fp>\u003Cp>(4) Save specified attachment\u003C\u002Fp>\u003Cp>View email information in the inbox:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 listmailofinbox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result saved as listmailofinbox.xml, obtain the corresponding email's ItemId from it\u003C\u002Fp>\u003Cp>View information of the specified attachment:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 getattachment\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Then enter the email's ItemId\u003C\u002Fp>\u003Cp>Command line outputs attachment name\u003C\u002Fp>\u003Cp>Result saved as getattachment.xml, obtain the corresponding attachment's Id from the file\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018752962_2_ccd76a318a.jpeg\">\u003C\u002Fp>\u003Cp>Save specified email:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 saveattachment\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Then enter the attachment's Id\u003C\u002Fp>\u003Cp>Automatically save attachments, distinguishing whether they are in text format\u003C\u002Fp>\u003Cp>Results saved as saveattachment.xml\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018765610_3_6bd24dd8bb.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the use of SOAP XML messages, the open-source code ewsManage.py, and implements access to Exchange resources using hashes\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article \"Exchange Web Service (EWS) Development Guide\", the tool ewsManage was open-sourced, enabling access to Exchange resources.\u003C\u002Fp>\u003Cp>This article will take a step further by utilizing SOAP XML messages to achieve access to Exchange resources using a hash.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Methods for accessing Exchange resources using a hash\u003C\u002Fli>\u003Cli>Usage of SOAP XML messages\u003C\u002Fli>\u003Cli>Open-source Python implementation code\u003C\u002Fli>\u003Cli>Code development details\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods for Accessing Exchange Resources Using a Hash\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article \"Penetration Techniques – Pass the Hash with Exchange Web Service\" introduced the method of logging into EWS using a hash.\u003C\u002Fp>\u003Cp>Based on previous research, this article will introduce methods for accessing Exchange resources after logging into EWS. Therefore, Python will continue to be chosen for program implementation, using EWS SOAP XML messages to access Exchange resources.\u003C\u002Fp>\u003Cp>For the format of EWS SOAP XML messages, there are two methods for reference:\u003C\u002Fp>\u003Cp>1. Search for information\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fexchange-web-services\u002Fget-started-with-ews-client-applications\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fews-xml-elements-in-exchange\u003C\u002Fp>\u003Cp>2. Packet capture analysis\u003C\u002Fp>\u003Cp>Configure Wireshark to capture plaintext communication data on the Exchange Server\u003C\u002Fp>\u003Cp>Use ewsManage to access Exchange resources\u003C\u002Fp>\u003Cp>Capture communication data to obtain the EWS SOAP XML message format corresponding to different operations, as shown in the example below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018734621_0_73173d5c01-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Using SOAP XML messages\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Compared to EWS Managed API, SOAP XML messages are more low-level and require consideration of more details.\u003C\u002Fp>\u003Ch3>1. View the number of emails in the inbox\u003C\u002Fh3>\u003Cp>XML format to send:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" \u003Cbr=\"\">               xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" \u003Cbr>               xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" \u003Cbr>               xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\"&gt;\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getfolder>\u003Cbr>      \u003Cm:foldershape>\u003Cbr>        \u003Ct:baseshape>Default\u003C\u002Ft:baseshape>\u003Cbr>      \u003C\u002Fm:foldershape>\u003Cbr>      \u003Cm:folderids>\u003Cbr>        \u003Ct:distinguishedfolderid id=\"inbox\">\u003Cbr>      \u003C\u002Ft:distinguishedfolderid>\u003C\u002Fm:folderids>\u003Cbr>    \u003C\u002Fm:getfolder>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Return content format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cs:envelope xmlns:s=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>\u003Cs:header>\u003Cbr>\u003Ch:serverversioninfo xmlns:h=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:xsd=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema\" xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" majorversion=\"15\" minorversion=\"0\" majorbuildnumber=\"847\" minorbuildnumber=\"31\">\u003Cbr>\u003C\u002Fh:serverversioninfo>\u003C\u002Fs:header>\u003Cbr>\u003Cs:body xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:xsd=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema\">\u003Cbr>\u003Cm:getfolderresponse xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\">\u003Cbr>\u003Cm:responsemessages>\u003Cbr>\u003Cm:getfolderresponsemessage responseclass=\"Success\">\u003Cbr>\u003Cm:responsecode>NoError\u003C\u002Fm:responsecode>\u003Cbr>\u003Cm:folders>\u003Cbr>\u003Ct:folder>\u003Cbr>\u003Ct:folderid id=\"AQAOAHRlc3QxQHRlc3QuY29tAC4AAAOeuRYNE6D6Q70cD0Q\u002Fs0RIAQAXa2D52NzfQYSx7xK5j92NAAACAQ0AAAA=\" changekey=\"AQAAABYAAAAXa2D52NzfQYSx7xK5j92NAAAAABK9\">\u003Cbr>\u003Ct:displayname>Inbox\u003C\u002Ft:displayname>\u003Cbr>\u003Ct:totalcount>6\u003C\u002Ft:totalcount>\u003Cbr>\u003Ct:childfoldercount>0\u003C\u002Ft:childfoldercount>\u003Cbr>\u003Ct:unreadcount>4\u003C\u002Ft:unreadcount>\u003Cbr>\u003C\u002Ft:folderid>\u003C\u002Ft:folder>\u003Cbr>\u003C\u002Fm:folders>\u003Cbr>\u003C\u002Fm:getfolderresponsemessage>\u003Cbr>\u003C\u002Fm:responsemessages>\u003Cbr>\u003C\u002Fm:getfolderresponse>\u003Cbr>\u003C\u002Fs:body>\u003Cbr>\u003C\u002Fs:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The response content reveals the total number of emails and unread emails in the inbox.\u003C\u002Fp>\u003Ch3>2. Retrieve inbox email information\u003C\u002Fh3>\u003Cp>XML format to send:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:finditem traversal=\"Shallow\">\u003Cbr>      \u003Cm:itemshape>\u003Cbr>        \u003Ct:baseshape>AllProperties\u003C\u002Ft:baseshape>\u003Cbr>        \u003Ct:bodytype>Text\u003C\u002Ft:bodytype>\u003Cbr>      \u003C\u002Fm:itemshape>\u003Cbr>      \u003Cm:indexedpageitemview maxentriesreturned=\"2147483647\" offset=\"0\" basepoint=\"Beginning\">\u003Cbr>      \u003Cm:parentfolderids>\u003Cbr>        \u003Ct:distinguishedfolderid id=\"inbox\">\u003Cbr>      \u003C\u002Ft:distinguishedfolderid>\u003C\u002Fm:parentfolderids>\u003Cbr>    \u003C\u002Fm:indexedpageitemview>\u003C\u002Fm:finditem>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The returned content can obtain the subject, sender-recipient relationship, and whether attachments are present for all emails in the inbox, but cannot display the body content or attachment names.\u003C\u002Fp>\u003Cp>The returned content can obtain the ItemId and ChangeKey corresponding to each email, thereby allowing access to the email content, attachment names, and Ids.\u003C\u002Fp>\u003Ch3>3. Obtain the specific content of a specified email\u003C\u002Fh3>\u003Cp>XML format sent:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getitem>\u003Cbr>      \u003Cm:itemshape>\u003Cbr>        \u003Ct:baseshape>AllProperties\u003C\u002Ft:baseshape>\u003Cbr>        \u003Ct:bodytype>Text\u003C\u002Ft:bodytype>\u003Cbr>      \u003C\u002Fm:itemshape>\u003Cbr>      \u003Cm:itemids>\u003Cbr>        \u003Ct:itemid id=\"{id}\" changekey=\"{key}\">\u003Cbr>      \u003C\u002Ft:itemid>\u003C\u002Fm:itemids>\u003Cbr>    \u003C\u002Fm:getitem>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Where {id} is the ItemId of the specified email, and {key} is the ChangeKey of the specified email\u003C\u002Fp>\u003Cp>Detailed information of the email, including the body content, can be obtained from the response\u003C\u002Fp>\u003Ch3>4. Get the attachment names of the specified email\u003C\u002Fh3>\u003Cp>XML format to send:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getitem>\u003Cbr>      \u003Cm:itemshape>\u003Cbr>        \u003Ct:baseshape>IdOnly\u003C\u002Ft:baseshape>\u003Cbr>        \u003Ct:additionalproperties>\u003Cbr>          \u003Ct:fielduri fielduri=\"item:Attachments\">\u003Cbr>        \u003C\u002Ft:fielduri>\u003C\u002Ft:additionalproperties>\u003Cbr>      \u003C\u002Fm:itemshape>\u003Cbr>      \u003Cm:itemids>\u003Cbr>        \u003Ct:itemid id=\"{id}\">\u003Cbr>      \u003C\u002Ft:itemid>\u003C\u002Fm:itemids>\u003Cbr>    \u003C\u002Fm:getitem>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>where {id} is the ItemId corresponding to the specified email\u003C\u002Fp>\u003Cp>Return content format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cs:envelope xmlns:s=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>\u003Cs:header>\u003Cbr>\u003Ch:serverversioninfo xmlns:h=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:xsd=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema\" xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" majorversion=\"15\" minorversion=\"0\" majorbuildnumber=\"847\" minorbuildnumber=\"31\" version=\"V2_8\">\u003Cbr>\u003C\u002Fh:serverversioninfo>\u003C\u002Fs:header>\u003Cbr>\u003Cs:body xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:xsd=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema\">\u003Cbr>\u003Cm:getitemresponse xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\">\u003Cbr>\u003Cm:responsemessages>\u003Cbr>\u003Cm:getitemresponsemessage responseclass=\"Success\">\u003Cbr>\u003Cm:responsecode>NoError\u003C\u002Fm:responsecode>\u003Cbr>\u003Cm:items>\u003Cbr>\u003Ct:message>\u003Cbr>\u003Ct:itemid id=\"AAMkADc2OGUyODVmLWY3NjktNDY2MC1iMzllLTM4MThjYzU4OGQ4YgBGAAAAAACeuRYNE6D6Q70cD0Q\u002Fs0RIBwAXa2D52NzfQYSx7xK5j92NAAAAAAENAAAXa2D52NzfQYSx7xK5j92NAAAAAAztAAA=\" changekey=\"CQAAABYAAAAXa2D52NzfQYSx7xK5j92NAAAAAAzk\">\u003Cbr>\u003Ct:attachments>\u003Cbr>\u003Ct:fileattachment>\u003Cbr>\u003Ct:attachmentid id=\"AAMkADc2OGUyODVmLWY3NjktNDY2MC1iMzllLTM4MThjYzU4OGQ4YgBGAAAAAACeuRYNE6D6Q70cD0Q\u002Fs0RIBwAXa2D52NzfQYSx7xK5j92NAAAAAAENAAAXa2D52NzfQYSx7xKj92NAAAAAAztAAABEgAQAJwa7iI1b4ZGoFo6F\u002FTfALM=\">\u003Cbr>\u003Ct:name>1.docx\u003C\u002Ft:name>\u003Cbr>\u003Ct:size>3013\u003C\u002Ft:size>\u003Cbr>\u003Ct:lastmodifiedtime>2020-05-21T01:17:07\u003C\u002Ft:lastmodifiedtime>\u003Cbr>\u003Ct:isinline>false\u003C\u002Ft:isinline>\u003Cbr>\u003Ct:iscontactphoto>false\u003C\u002Ft:iscontactphoto>\u003Cbr>\u003C\u002Ft:attachmentid>\u003C\u002Ft:fileattachment>\u003Cbr>\u003C\u002Ft:attachments>\u003Cbr>\u003Ct:hasattachments>true\u003C\u002Ft:hasattachments>\u003Cbr>\u003C\u002Ft:itemid>\u003C\u002Ft:message>\u003Cbr>\u003C\u002Fm:items>\u003Cbr>\u003C\u002Fm:getitemresponsemessage>\u003Cbr>\u003C\u002Fm:responsemessages>\u003Cbr>\u003C\u002Fm:getitemresponse>\u003Cbr>\u003C\u002Fs:body>\u003Cbr>\u003C\u002Fs:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The attachment name can be obtained from the returned content, but the attachment content cannot be retrieved.\u003C\u002Fp>\u003Cp>The corresponding Id for each attachment can be obtained from the returned content, thereby allowing retrieval of the attachment type and content.\u003C\u002Fp>\u003Ch3>5. Obtain the content of the specified attachment\u003C\u002Fh3>\u003Cp>XML format to be sent:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getattachment>\u003Cbr>      \u003Cm:attachmentids>\u003Cbr>        \u003Ct:attachmentid id=\"{id}\">\u003Cbr>      \u003C\u002Ft:attachmentid>\u003C\u002Fm:attachmentids>\u003Cbr>    \u003C\u002Fm:getattachment>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>where {id} is the Id corresponding to the specified attachment\u003C\u002Fp>\u003Cp>Return content format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cs:envelope xmlns:s=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>\u003Cs:header>\u003Cbr>\u003Ch:serverversioninfo xmlns:h=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:xsd=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema\" xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" majorversion=\"15\" minorversion=\"0\" majorbuildnumber=\"847\" minorbuildnumber=\"31\" version=\"V2_8\">\u003Cbr>\u003C\u002Fh:serverversioninfo>\u003C\u002Fs:header>\u003Cbr>\u003Cs:body xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:xsd=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema\">\u003Cbr>\u003Cm:getattachmentresponse xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\">\u003Cbr>\u003Cm:responsemessages>\u003Cbr>\u003Cm:getattachmentresponsemessage responseclass=\"Success\">\u003Cbr>\u003Cm:responsecode>NoError\u003C\u002Fm:responsecode>\u003Cbr>\u003Cm:attachments>\u003Cbr>\u003Ct:fileattachment>\u003Cbr>\u003Ct:attachmentid id=\"AAMkADc2OGUyODVmLWY3NjktNDY2MC1iMzllLTM4MThjYzU4OGQ4YgBGAAAAAACeuRYNE6D6Q70cD0Q\u002Fs0RIBwAXa2D52NzfQYSx7xK5j92NAAAAAAENAAAXa2D52NzfQYSx7xK5j92NAAAAAAzvAAABEgAQAK2JBdCt\u002FlxColLkCuqo5hw=\">\u003Cbr>\u003Ct:name>1.txt\u003C\u002Ft:name>\u003Cbr>\u003Ct:contenttype>text\u002Fplain\u003C\u002Ft:contenttype>\u003Cbr>\u003Ct:content>{xxxxxxx}\u003C\u002Ft:content>\u003Cbr>\u003C\u002Ft:attachmentid>\u003C\u002Ft:fileattachment>\u003Cbr>\u003C\u002Fm:attachments>\u003Cbr>\u003C\u002Fm:getattachmentresponsemessage>\u003Cbr>\u003C\u002Fm:responsemessages>\u003Cbr>\u003C\u002Fm:getattachmentresponse>\u003Cbr>\u003C\u002Fs:body>\u003Cbr>\u003C\u002Fs:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The {xxxxxxx} is base64-encoded content, which can be decoded to obtain the attachment's content.\u003C\u002Fp>\u003Cp>Note the attachment type: if it is text, it indicates a text type; otherwise, the attachment must be saved in binary format.\u003C\u002Fp>\u003Ch2>0x04 Open Source Python Implementation Code\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The code has been open-sourced at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Implemented using Python. Impacket must be installed before running the script.\u003C\u002Fp>\u003Cp>Installation method: pip install Impacket\u003C\u002Fp>\u003Cp>Supports login with both plaintext and NTLM hash\u003C\u002Fp>\u003Cp>Functionally, it is largely consistent with ewsManage\u003C\u002Fp>\u003Cp>Supports the following features:\u003C\u002Fp>\u003Cul>\u003Cli>View the number of emails in the inbox\u003C\u002Fli>\u003Cli>View the number of emails in the outbox\u003C\u002Fli>\u003Cli>View inbox email information\u003C\u002Fli>\u003Cli>View outbox email information\u003C\u002Fli>\u003Cli>View detailed information of a specified email\u003C\u002Fli>\u003Cli>View information of a specified attachment\u003C\u002Fli>\u003Cli>Save specified attachments\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Usage example:\u003C\u002Fp>\u003Cp>(1) Check the number of emails in the inbox (using plaintext login)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 getfolderofinbox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) View email information in the inbox (using hash login)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 ntlmhash test.com user1 c5a237b7e9d8e708d8436b6148a25fa1 listmailofinbox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) View specific information of a specified email\u003C\u002Fp>\u003Cp>View email information in the inbox:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 listmailofinbox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Results are saved as listmailofinbox.xml, obtain the corresponding email's ItemId and ChangeKey from the file\u003C\u002Fp>\u003Cp>View specific information of a specified email:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 getmail\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Then input the email's ItemId and ChangeKey\u003C\u002Fp>\u003Cp>Final results are saved as getmail.xml\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018746208_1_ab0f030b1e-1.jpeg\">\u003C\u002Fp>\u003Cp>(4) Save specified attachment\u003C\u002Fp>\u003Cp>View email information in the inbox:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 listmailofinbox\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result saved as listmailofinbox.xml, obtain the corresponding email's ItemId from it\u003C\u002Fp>\u003Cp>View information of the specified attachment:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 getattachment\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Then enter the email's ItemId\u003C\u002Fp>\u003Cp>Command line outputs attachment name\u003C\u002Fp>\u003Cp>Result saved as getattachment.xml, obtain the corresponding attachment's Id from the file\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018752962_2_ccd76a318a-1.jpeg\">\u003C\u002Fp>\u003Cp>Save specified email:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 saveattachment\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Then enter the attachment's Id\u003C\u002Fp>\u003Cp>Automatically save attachments, distinguishing whether they are in text format\u003C\u002Fp>\u003Cp>Results saved as saveattachment.xml\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018765610_3_6bd24dd8bb-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the use of SOAP XML messages, the open-source code ewsManage.py, and implements access to Exchange resources using hashes\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1331,"Onedaysec",5,"published","2026-02-02T08:04:56.384Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"EWS SOAP XML Guide: Access Exchange with Hash & Python","Exchange Web Services, EWS, SOAP XML, pass the hash, Python, email access, attachment retrieval, Exchange development",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],366,365,363,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.895Z","2026-07-23T16:01:26.767Z","draft","2026-07-23T16:05:38.246Z"]