[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fY9B9MTkunYXrojWTKs09Tvw2IJ_8PyqpEsQTLC1ZojQ":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},343,"How does Jason compare with other open-source Exchange brute-force tools like MailSniper and Ruler?","Jason, [MailSniper](https:\u002F\u002Fgithub.com\u002Fdafthack\u002FMailSniper), and [Ruler](https:\u002F\u002Fgithub.com\u002Fsensepost\u002Fruler) all brute-force Exchange accounts by accessing web resources and checking for 401 vs successful responses. Jason uses EWS and OAB endpoints with a GUI and supports multithreading, similar to MailSniper (PowerShell, multithreading, CLI) and Ruler (Go, no multithreading, CLI). The article concludes that Jason does not introduce any novel threat, as its principles are identical to existing tools.","\u003Cp>Jason, [MailSniper](https:\u002F\u002Fgithub.com\u002Fdafthack\u002FMailSniper), and [Ruler](https:\u002F\u002Fgithub.com\u002Fsensepost\u002Fruler) all brute-force Exchange accounts by accessing web resources and checking for 401 vs successful responses. Jason uses EWS and OAB endpoints with a GUI and supports multithreading, similar to MailSniper (PowerShell, multithreading, CLI) and Ruler (Go, no multithreading, CLI). The article concludes that Jason does not introduce any novel threat, as its principles are identical to existing tools.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fanalysis-of-apt34-leaked-tools-jason\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-jason-compare-with-other-open-source-exchange-brute-force-tools-like-ma-1777484088176","MailSniper, Ruler, open-source, exchange brute-force, multithreading, comparison",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},87,"Analysis of APT34 Leaked Tools - Jason","analysis-of-apt34-leaked-tools-jason","Technical analysis of APT34's leaked Jason tool, fixing bugs for Exchange account brute-force attacks, with comparisons to open-source tools.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Jason is another tool leaked by Lab Dookhtegan on June 3, 2019, used for brute-force attacks on Exchange accounts\u003C\u002Fp>\u003Cp>However, although the leaked tool includes source code, it contains some bugs and cannot function properly\u003C\u002Fp>\u003Cp>This article will not analyze the connection between Jason and APT34, but will only focus on technical research: fixing Jason's bugs, restoring its functionality, analyzing the techniques used, and making horizontal comparisons with other open-source tools\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Previous analysis articles on APT34:\u003C\u002Fp>\u003Cp>\"Analysis of APT34 Leaked Tools - PoisonFrog and Glimpse\"\u003C\u002Fp>\u003Cp>\"Analysis of APT34 Leaked Tools - HighShell and HyperShell\"\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Open-source information about Jason\u003C\u002Fli>\u003Cli>Fixing Jason's bugs\u003C\u002Fli>\u003Cli>Actual testing of Jason\u003C\u002Fli>\u003Cli>Horizontal comparison with other open-source tools\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Open-source materials of Jason\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Jason was first leaked on a Telegram channel: https:\u002F\u002Ft.me\u002Flab_dookhtegana\u003C\u002Fp>\u003Cp>p3pperp0tts uploaded it to GitHub at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fp3pperp0tts\u002FAPT34\u002Ftree\u002Fmaster\u002FJason\u003C\u002Fp>\u003Cp>The decompiled_code folder contains the source code of Jason\u003C\u002Fp>\u003Cp>Jason uses EWS Managed API to access Exchange resources\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details on using EWS Managed API, refer to the previous article \"Exchange Web Service (EWS) Development Guide\"\u003C\u002Fp>\u003Cp>After simple fixes, I was able to compile it successfully in VS2015\u003C\u002Fp>\u003Cp>However, in the test environment, Jason failed to recognize the correct mailbox username and password, and all test results were unsuccessful\u003C\u002Fp>\u003Ch2>0x03 Fixing Jason's bug\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Compilation environment: VS2015\u003C\u002Fp>\u003Cp>To restore normal functionality, the source code needs to be modified at the following 4 locations\u003C\u002Fp>\u003Ch3>1. Add a reference to Microsoft.Exchange.WebServices.dll\u003C\u002Fh3>\u003Cp>Here, I placed Microsoft.Exchange.WebServices.dll in the same directory as the project and added a reference to it\u003C\u002Fp>\u003Ch3>2. Bug fix for certificate trust policy\u003C\u002Fh3>\u003Cp>Location: Form1.cs\u003C\u002Fp>\u003Cp>Original code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ServicePointManager.ServerCertificateValidationCallback = ((object \u003Cp0>, X509Certificate \u003Cp1>, X509Chain \u003Cp2>, SslPolicyErrors \u003Cp3>) =&gt; true);\u003C\u002Fp3>\u003C\u002Fp2>\u003C\u002Fp1>\u003C\u002Fp0>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modified code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ServicePointManager.ServerCertificateValidationCallback = (sender, certificate, chain, sslPolicyErrors) =&gt; { return true; };\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Bug fix for variable assignment\u003C\u002Fh3>\u003Cp>Location: Form1.cs\u003C\u002Fp>\u003Cp>(1) There are two locations in total\u003C\u002Fp>\u003Cp>Original code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.AppLocation + \"out.txt\";\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modified code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.AppLocation = MainConfig.AppLocation + \"out.txt\";\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) There are two locations\u003C\u002Fp>\u003Cp>Original code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.UsernameStart + userClass.Username + MainConfig.UsernameEnd;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modified code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>userClass.Username = MainConfig.UsernameStart + userClass.Username + MainConfig.UsernameEnd;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Issues with EWS and OAB judgment\u003C\u002Fh3>\u003Cp>After testing, the value of variable MainConfig.Method is always empty\u003C\u002Fp>\u003Cp>Need to fix the bug where MainConfig.Method cannot retrieve a value\u003C\u002Fp>\u003Cp>Location: Form1.cs\u003C\u002Fp>\u003Cp>Original code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.Method = this.cmbMethod.SelectedText;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modified code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.Method = (string)this.cmbMethod.SelectedItem;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>I have uploaded the complete functional project to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x04 Actual Test Jason\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After successful compilation, the file Jason.exe is generated\u003C\u002Fp>\u003Cp>The file Microsoft.Exchange.WebServices.dll is required in the same directory for the program to run properly\u003C\u002Fp>\u003Cp>After the program starts, the following configurations need to be set:\u003C\u002Fp>\u003Ch3>1. Exchange Address\u003C\u002Fh3>\u003Cp>Enter the URL of the Exchange server\u003C\u002Fp>\u003Cp>In my test environment, the Exchange Address is: https:\u002F\u002F192.168.206.17\u003C\u002Fp>\u003Ch3>2. Exchange Version\u003C\u002Fh3>\u003Cp>Select the corresponding version\u003C\u002Fp>\u003Cp>Choosing a lower version here can be compatible with higher versions of the Exchange server\u003C\u002Fp>\u003Ch3>3. BF Method\u003C\u002Fh3>\u003Cp>Three options:\u003C\u002Fp>\u003Cul>\u003Cli>EWS (Exchange Web Service)\u003C\u002Fli>\u003Cli>OAB (Offline Address Book)\u003C\u002Fli>\u003Cli>Full\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Typically select EWS\u003C\u002Fp>\u003Ch3>4. Username File\u003C\u002Fh3>\u003Cp>Username dictionary file\u003C\u002Fp>\u003Cp>Format can refer to the format indicated in PassSample.txt\u003C\u002Fp>\u003Cp>In my test environment, the format example I used is:\u003C\u002Fp>\u003Cp>test1@test.com\u003C\u002Fp>\u003Cp>admin@test.com\u003C\u002Fp>\u003Ch3>5. Password File\u003C\u002Fh3>\u003Cp>Password dictionary file\u003C\u002Fp>\u003Ch3>6. Number of Threads\u003C\u002Fh3>\u003Cp>Set the number of scanning threads\u003C\u002Fp>\u003Ch3>7. Generate Pass\u003C\u002Fh3>\u003Cp>Click to display the dictionary used for brute force attacks\u003C\u002Fp>\u003Ch3>8.Generate Pass Per\u003C\u002Fh3>\u003Cp>Click to generate a folder named PasswordPerUser, containing txt files named after each username with password dictionary content\u003C\u002Fp>\u003Ch3>9.Add to Username Start\u003C\u002Fh3>\u003Cp>Generate new users by adding input characters before the username\u003C\u002Fp>\u003Cp>Not recommended to set in test environments\u003C\u002Fp>\u003Ch3>10.Add to Username End\u003C\u002Fh3>\u003Cp>Generate new users by adding input characters after the username\u003C\u002Fp>\u003Cp>Not recommended to set in test environments\u003C\u002Fp>\u003Cp>In my test environment, the configuration is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018723006_0_745fc753e4.jpeg\">\u003C\u002Fp>\u003Cp>After successful brute force attack, generate log file out-year-month-day-hour-minute-second.txt, saving usernames and corresponding passwords\u003C\u002Fp>\u003Ch2>0x05 Horizontal comparison with other open-source tools\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1.Jason\u003C\u002Fh3>\u003Cul>\u003Cli>C# Implementation\u003C\u002Fli>\u003Cli>Brute force attack locations for Exchange:\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Fews\u002Fexchange.asmx\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Foab\u003C\u002Fli>\u003Cli>Supports multithreading\u003C\u002Fli>\u003Cli>GUI operation\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2.MailSniper\u003C\u002Fh3>\u003Cul>\u003Cli>https:\u002F\u002Fgithub.com\u002Fdafthack\u002FMailSniper\u003C\u002Fli>\u003Cli>PowerShell implementation\u003C\u002Fli>\u003Cli>Brute force attack locations for Exchange:\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Fews\u002Fexchange.asmx\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Fowa\u003C\u002Fli>\u003Cli>Supports multithreading\u003C\u002Fli>\u003Cli>Command-line operation\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>3.Ruler\u003C\u002Fh3>\u003Cul>\u003Cli>https:\u002F\u002Fgithub.com\u002Fsensepost\u002Fruler\u003C\u002Fli>\u003Cli>Go implementation\u003C\u002Fli>\u003Cli>Location for brute-forcing Exchange:\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Fautodiscover\u002Fautodiscover.xml\u003C\u002Fli>\u003Cli>Does not support multithreading\u003C\u002Fli>\u003Cli>Command-line operation\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For brute-forcing Exchange accounts, the principles are largely similar: all involve accessing Exchange web resources. A 401 response indicates authentication failure, while obtaining the expected result indicates correct user credentials.\u003C\u002Fp>\u003Cp>Compared to MailSniper and Ruler, Jason shares essentially the same principles and functionality. Personally, I believe this tool does not pose a risk of widespread abuse nor will it lead to advancements in malware techniques.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article describes how to fix Jason's bug, analyzes its underlying technology, provides a comparative analysis with other open-source tools, and concludes: personally, I believe this tool does not pose a risk of widespread abuse nor will it lead to advancements in malware techniques.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Jason is another tool leaked by Lab Dookhtegan on June 3, 2019, used for brute-force attacks on Exchange accounts\u003C\u002Fp>\u003Cp>However, although the leaked tool includes source code, it contains some bugs and cannot function properly\u003C\u002Fp>\u003Cp>This article will not analyze the connection between Jason and APT34, but will only focus on technical research: fixing Jason's bugs, restoring its functionality, analyzing the techniques used, and making horizontal comparisons with other open-source tools\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Previous analysis articles on APT34:\u003C\u002Fp>\u003Cp>\"Analysis of APT34 Leaked Tools - PoisonFrog and Glimpse\"\u003C\u002Fp>\u003Cp>\"Analysis of APT34 Leaked Tools - HighShell and HyperShell\"\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Open-source information about Jason\u003C\u002Fli>\u003Cli>Fixing Jason's bugs\u003C\u002Fli>\u003Cli>Actual testing of Jason\u003C\u002Fli>\u003Cli>Horizontal comparison with other open-source tools\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Open-source materials of Jason\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Jason was first leaked on a Telegram channel: https:\u002F\u002Ft.me\u002Flab_dookhtegana\u003C\u002Fp>\u003Cp>p3pperp0tts uploaded it to GitHub at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fp3pperp0tts\u002FAPT34\u002Ftree\u002Fmaster\u002FJason\u003C\u002Fp>\u003Cp>The decompiled_code folder contains the source code of Jason\u003C\u002Fp>\u003Cp>Jason uses EWS Managed API to access Exchange resources\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details on using EWS Managed API, refer to the previous article \"Exchange Web Service (EWS) Development Guide\"\u003C\u002Fp>\u003Cp>After simple fixes, I was able to compile it successfully in VS2015\u003C\u002Fp>\u003Cp>However, in the test environment, Jason failed to recognize the correct mailbox username and password, and all test results were unsuccessful\u003C\u002Fp>\u003Ch2>0x03 Fixing Jason's bug\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Compilation environment: VS2015\u003C\u002Fp>\u003Cp>To restore normal functionality, the source code needs to be modified at the following 4 locations\u003C\u002Fp>\u003Ch3>1. Add a reference to Microsoft.Exchange.WebServices.dll\u003C\u002Fh3>\u003Cp>Here, I placed Microsoft.Exchange.WebServices.dll in the same directory as the project and added a reference to it\u003C\u002Fp>\u003Ch3>2. Bug fix for certificate trust policy\u003C\u002Fh3>\u003Cp>Location: Form1.cs\u003C\u002Fp>\u003Cp>Original code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ServicePointManager.ServerCertificateValidationCallback = ((object \u003Cp0>, X509Certificate \u003Cp1>, X509Chain \u003Cp2>, SslPolicyErrors \u003Cp3>) =&gt; true);\u003C\u002Fp3>\u003C\u002Fp2>\u003C\u002Fp1>\u003C\u002Fp0>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modified code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ServicePointManager.ServerCertificateValidationCallback = (sender, certificate, chain, sslPolicyErrors) =&gt; { return true; };\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Bug fix for variable assignment\u003C\u002Fh3>\u003Cp>Location: Form1.cs\u003C\u002Fp>\u003Cp>(1) There are two locations in total\u003C\u002Fp>\u003Cp>Original code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.AppLocation + \"out.txt\";\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modified code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.AppLocation = MainConfig.AppLocation + \"out.txt\";\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) There are two locations\u003C\u002Fp>\u003Cp>Original code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.UsernameStart + userClass.Username + MainConfig.UsernameEnd;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modified code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>userClass.Username = MainConfig.UsernameStart + userClass.Username + MainConfig.UsernameEnd;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Issues with EWS and OAB judgment\u003C\u002Fh3>\u003Cp>After testing, the value of variable MainConfig.Method is always empty\u003C\u002Fp>\u003Cp>Need to fix the bug where MainConfig.Method cannot retrieve a value\u003C\u002Fp>\u003Cp>Location: Form1.cs\u003C\u002Fp>\u003Cp>Original code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.Method = this.cmbMethod.SelectedText;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modified code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.Method = (string)this.cmbMethod.SelectedItem;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>I have uploaded the complete functional project to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x04 Actual Test Jason\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After successful compilation, the file Jason.exe is generated\u003C\u002Fp>\u003Cp>The file Microsoft.Exchange.WebServices.dll is required in the same directory for the program to run properly\u003C\u002Fp>\u003Cp>After the program starts, the following configurations need to be set:\u003C\u002Fp>\u003Ch3>1. Exchange Address\u003C\u002Fh3>\u003Cp>Enter the URL of the Exchange server\u003C\u002Fp>\u003Cp>In my test environment, the Exchange Address is: https:\u002F\u002F192.168.206.17\u003C\u002Fp>\u003Ch3>2. Exchange Version\u003C\u002Fh3>\u003Cp>Select the corresponding version\u003C\u002Fp>\u003Cp>Choosing a lower version here can be compatible with higher versions of the Exchange server\u003C\u002Fp>\u003Ch3>3. BF Method\u003C\u002Fh3>\u003Cp>Three options:\u003C\u002Fp>\u003Cul>\u003Cli>EWS (Exchange Web Service)\u003C\u002Fli>\u003Cli>OAB (Offline Address Book)\u003C\u002Fli>\u003Cli>Full\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Typically select EWS\u003C\u002Fp>\u003Ch3>4. Username File\u003C\u002Fh3>\u003Cp>Username dictionary file\u003C\u002Fp>\u003Cp>Format can refer to the format indicated in PassSample.txt\u003C\u002Fp>\u003Cp>In my test environment, the format example I used is:\u003C\u002Fp>\u003Cp>test1@test.com\u003C\u002Fp>\u003Cp>admin@test.com\u003C\u002Fp>\u003Ch3>5. Password File\u003C\u002Fh3>\u003Cp>Password dictionary file\u003C\u002Fp>\u003Ch3>6. Number of Threads\u003C\u002Fh3>\u003Cp>Set the number of scanning threads\u003C\u002Fp>\u003Ch3>7. Generate Pass\u003C\u002Fh3>\u003Cp>Click to display the dictionary used for brute force attacks\u003C\u002Fp>\u003Ch3>8.Generate Pass Per\u003C\u002Fh3>\u003Cp>Click to generate a folder named PasswordPerUser, containing txt files named after each username with password dictionary content\u003C\u002Fp>\u003Ch3>9.Add to Username Start\u003C\u002Fh3>\u003Cp>Generate new users by adding input characters before the username\u003C\u002Fp>\u003Cp>Not recommended to set in test environments\u003C\u002Fp>\u003Ch3>10.Add to Username End\u003C\u002Fh3>\u003Cp>Generate new users by adding input characters after the username\u003C\u002Fp>\u003Cp>Not recommended to set in test environments\u003C\u002Fp>\u003Cp>In my test environment, the configuration is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018723006_0_745fc753e4-1.jpeg\">\u003C\u002Fp>\u003Cp>After successful brute force attack, generate log file out-year-month-day-hour-minute-second.txt, saving usernames and corresponding passwords\u003C\u002Fp>\u003Ch2>0x05 Horizontal comparison with other open-source tools\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1.Jason\u003C\u002Fh3>\u003Cul>\u003Cli>C# Implementation\u003C\u002Fli>\u003Cli>Brute force attack locations for Exchange:\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Fews\u002Fexchange.asmx\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Foab\u003C\u002Fli>\u003Cli>Supports multithreading\u003C\u002Fli>\u003Cli>GUI operation\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2.MailSniper\u003C\u002Fh3>\u003Cul>\u003Cli>https:\u002F\u002Fgithub.com\u002Fdafthack\u002FMailSniper\u003C\u002Fli>\u003Cli>PowerShell implementation\u003C\u002Fli>\u003Cli>Brute force attack locations for Exchange:\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Fews\u002Fexchange.asmx\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Fowa\u003C\u002Fli>\u003Cli>Supports multithreading\u003C\u002Fli>\u003Cli>Command-line operation\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>3.Ruler\u003C\u002Fh3>\u003Cul>\u003Cli>https:\u002F\u002Fgithub.com\u002Fsensepost\u002Fruler\u003C\u002Fli>\u003Cli>Go implementation\u003C\u002Fli>\u003Cli>Location for brute-forcing Exchange:\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Fautodiscover\u002Fautodiscover.xml\u003C\u002Fli>\u003Cli>Does not support multithreading\u003C\u002Fli>\u003Cli>Command-line operation\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For brute-forcing Exchange accounts, the principles are largely similar: all involve accessing Exchange web resources. A 401 response indicates authentication failure, while obtaining the expected result indicates correct user credentials.\u003C\u002Fp>\u003Cp>Compared to MailSniper and Ruler, Jason shares essentially the same principles and functionality. Personally, I believe this tool does not pose a risk of widespread abuse nor will it lead to advancements in malware techniques.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article describes how to fix Jason's bug, analyzes its underlying technology, provides a comparative analysis with other open-source tools, and concludes: personally, I believe this tool does not pose a risk of widespread abuse nor will it lead to advancements in malware techniques.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1357,"Onedaysec",4,"published","2026-02-02T08:06:13.162Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Fix APT34 Jason Tool Bugs & Exchange Brute-Force Analysis","APT34, Jason tool, Exchange brute-force, EWS API, bug fixes, cybersecurity analysis",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46,47],345,344,342,341,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.040Z","2026-07-23T16:01:24.781Z","draft","2026-07-23T16:05:29.697Z"]