[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCshER8ZN-Pxagh-iX8av3gsBMnrQFadFuTdmQPXTid4":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},431,"How does the NTLM Challenge fit into Pass the Hash attacks against Exchange?","In NTLM authentication, the server sends a random Challenge (16-byte nonce) to the client. During a Pass the Hash attack, the attacker uses the stolen NTLM hash to encrypt this Challenge, producing the correct response. The server then verifies the response, granting access if it matches. This is identical to the normal process but uses the hash directly instead of deriving it from a password. The article details the full exchange in the [Penetration Techniques - Pass the Hash with Exchange Web Service](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-exchange-web-service) article.","\u003Cp>In NTLM authentication, the server sends a random Challenge (16-byte nonce) to the client. During a Pass the Hash attack, the attacker uses the stolen NTLM hash to encrypt this Challenge, producing the correct response. The server then verifies the response, granting access if it matches. This is identical to the normal process but uses the hash directly instead of deriving it from a password. The article details the full exchange in the [Penetration Techniques - Pass the Hash with Exchange Web Service](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-exchange-web-service) article.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-exchange-web-service\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-the-ntlm-challenge-fit-into-pass-the-hash-attacks-against-exchange-1777483955724","NTLM Challenge, Challenge-Response, hash encryption, authentication bypass",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},108,"Penetration Techniques - Pass the Hash with Exchange Web Service","penetration-techniques-pass-the-hash-with-exchange-web-service","Learn how to use hash to log into Exchange Web Service (EWS) with penetration techniques, including decryption methods and open-source tools.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article \"Penetration Techniques - Pass the Hash with Remote Desktop Protocol,\" we introduced the method of using hash to log into RDP. This article will continue to introduce the method of using hash to log into EWS.\u003C\u002Fp>\u003Cp>We know that using mimikatz's over pass the hash and EWS's login with current credentials can achieve hash-based login to EWS. For related details, refer to \"Exchange Web Service (EWS) Development Guide\"%E5%BC%80%E5%8F%91%E6%8C%87%E5%8D%97)\u003C\u002Fp>\u003Cp>However, the drawback is that it requires administrator privileges and operations on the lsass process, making it impossible to authenticate multiple users simultaneously.\u003C\u002Fp>\u003Cp>Therefore, this article will introduce a more universal method, an open-source implementation script, and document the thought process and development procedure.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Decrypting Exchange communication data\u003C\u002Fli>\u003Cli>The idea of using hash to log into EWS\u003C\u002Fli>\u003Cli>Open-source code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Decrypting Exchange Communication Data\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Exchange uses the TLS protocol by default to encrypt data, and we can only capture encrypted content through Wireshark packet capture, which requires decryption.\u003C\u002Fp>\u003Cp>Here, we introduce methods for capturing plaintext communication data on both Exchange Server and Exchange Client.\u003C\u002Fp>\u003Ch3>1. Method for capturing plaintext communication data on Exchange Server\u003C\u002Fh3>\u003Ch4>(1) Exporting certificate files on Exchange Server\u003C\u002Fh4>\u003Cp>Using mimikatz, the command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe crypto::capi \"crypto::certificates \u002Fsystemstore:local_machine \u002Fstore:my \u002Fexport\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Without using the command crypto::capi, it is not possible to export certificate files with private keys (pfx files).\u003C\u002Fp>\u003Cp>This command will export multiple certificate files, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017381637_0_5ad8049833.jpeg\">\u003C\u002Fp>\u003Cp>To find the certificate file used for Exchange communication data, we can use the following method:\u003C\u002Fp>\u003Cp>Access the Exchange login page and locate the corresponding certificate file by checking the certificate's validity period, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017400698_1_3fd6bfd4d2.jpeg\">\u003C\u002Fp>\u003Cp>Certificate information can also be obtained via command line, with code available for reference in an open-source project.\u003C\u002Fp>\u003Cp>Test as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017447371_2_054b954646.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Configure Wireshark\u003C\u002Fh4>\u003Cp>Edit -&gt; Preferences...\u003C\u002Fp>\u003Cp>Protocols -&gt; TLS\u003C\u002Fp>\u003Cp>Select RSA keys list\u003C\u002Fp>\u003Cp>Fill in configuration information, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017468998_3_06510e5e1c.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Disable ECDH key exchange algorithm\u003C\u002Fh4>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechcommunity.microsoft.com\u002Ft5\u002Fcore-infrastructure-and-security\u002Fdemystifying-schannel\u002Fba-p\u002F259233#\u003C\u002Fp>\u003Cp>CMD command to disable ECDH via registry:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\\KeyExchangeAlgorithms\\ECDH \u002Fv Enabled \u002Ft REG_DWORD \u002Fd 0 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After disabling, use SSLCertScan again to obtain certificate information, Key Exchange Algorithm changes from ECDH Ephemeral to RsaKeyX\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017482629_4_6ece131842.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the Exchange Server configuration is complete. Capture the data again to obtain plaintext communication data, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017493044_5_62d40d02c5.jpeg\">\u003C\u002Fp>\u003Ch3>2. Method for Capturing Plaintext Communication Data from Exchange Client\u003C\u002Fh3>\u003Ch4>(1) Add environment variable\u003C\u002Fh4>\u003Cp>Variable name SSLKEYLOGFILE, value is the file path\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017502232_6_c403961a59.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Configure Wireshark\u003C\u002Fh4>\u003Cp>Edit -&gt; Preferences...\u003C\u002Fp>\u003Cp>Protocols -&gt; TLS\u003C\u002Fp>\u003Cp>Set (Pre)-Master-Secret log filename to C:\\test\\sslkey.log\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017507734_7_454316afe6.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the Exchange Client configuration is complete\u003C\u002Fp>\u003Cp>Open the Chrome browser, access Exchange, and use Wireshark to obtain plaintext data, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017513552_8_42424b03fd.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Approach to Logging into EWS Using Hash\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Using Mimikatz's over pass the hash and EWS's login with current credentials enables hash-based login to EWS. We captured data on both Exchange Server and Exchange Client, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017519149_9_128e80185a.jpeg\">\u003C\u002Fp>\u003Cp>It can be seen that the authentication process here uses NTLM Over HTTP Protocol\u003C\u002Fp>\u003Cp>For details on NTLM Over HTTP Protocol, refer to the previous article 'Penetration Techniques - Obtaining Net-NTLM Hash via HTTP Protocol'\u003C\u002Fp>\u003Cp>Authentication Process:\u003C\u002Fp>\u003Cp>1. The client sends a GET request to the server to obtain webpage content\u003C\u002Fp>\u003Cp>2. Since NTLM authentication is enabled on the server, it returns 401, indicating NTLM authentication is required\u003C\u002Fp>\u003Cp>3. The client initiates NTLM authentication and sends a negotiation message to the server\u003C\u002Fp>\u003Cp>4. Upon receiving the message, the server generates a 16-bit random number (known as Challenge) and sends it back to the client in plaintext\u003C\u002Fp>\u003Cp>5. After receiving the Challenge, the client encrypts it using the input password hash to generate a response, which is then sent to the server\u003C\u002Fp>\u003Cp>6. The server receives the encrypted response from the client, performs the same computation, and compares the results. If they match, subsequent services are provided; otherwise, authentication fails\u003C\u002Fp>\u003Cp>Regarding step 5: 'Encrypt the Challenge using the input password hash'\u003C\u002Fp>\u003Cp>If we directly pass the hash and encrypt the Challenge, we can achieve the same functionality.\u003C\u002Fp>\u003Cp>At this point, we have derived the implementation approach for using hash to log into ews:\u003C\u002Fp>\u003Cp>Simulate NTLM Over HTTP Protocol, directly pass the hash, encrypt the Challenge to generate a response, and send the response to the server.\u003C\u002Fp>\u003Ch2>0x04 Program Implementation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Here, Python is chosen for implementation, with the advantage of directly calling Impacket to implement NTLM Over HTTP Protocol.\u003C\u002Fp>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fdirkjanm\u002FPrivExchange\u002Fblob\u002Fmaster\u002Fprivexchange.py\u003C\u002Fp>\u003Cp>Before running the script, Impacket needs to be installed.\u003C\u002Fp>\u003Cp>Installation method: pip install Impacket\u003C\u002Fp>\u003Cp>My implementation code has been uploaded to GitHub, with the address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code supports verification for both plaintext and NTLM hash.\u003C\u002Fp>\u003Cp>Verifying plaintext, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017523227_10_3af96881d9.jpeg\">\u003C\u002Fp>\u003Cp>Verify hash, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017525554_11_74f12950af.jpeg\">\u003C\u002Fp>\u003Cp>After successful verification, my code will proceed to send a SOAP command to retrieve inbox information\u003C\u002Fp>\u003Cp>For SOAP command format reference, please see:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fews-operations-in-exchange\u003C\u002Fp>\u003Cp>Note that the SOAP command in the documentation needs format adjustment, otherwise it returns error 500 with the message: An internal server error occurred. The operation failed.\u003C\u002Fp>\u003Cp>Format adjustment example:\u003C\u002Fp>\u003Cp>The SOAP format in https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fgetfolder-operation is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\" \u003Cbr=\"\">   xmlns:t=\"https:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\"&gt;\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cgetfolder xmlns=\"https:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" \u003Cbr=\"\">               xmlns:t=\"https:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\"&gt;\u003Cbr>      \u003Cfoldershape>\u003Cbr>        \u003Ct:baseshape>Default\u003C\u002Ft:baseshape>\u003Cbr>      \u003C\u002Ffoldershape>\u003Cbr>      \u003Cfolderids>\u003Cbr>        \u003Ct:distinguishedfolderid id=\"inbox\">\u003Cbr>      \u003C\u002Ft:distinguishedfolderid>\u003C\u002Ffolderids>\u003Cbr>    \u003C\u002Fgetfolder>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The formatted content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" \u003Cbr=\"\">               xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" \u003Cbr>               xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" \u003Cbr>               xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\"&gt;\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getfolder>\u003Cbr>      \u003Cm:foldershape>\u003Cbr>        \u003Ct:baseshape>Default\u003C\u002Ft:baseshape>\u003Cbr>      \u003C\u002Fm:foldershape>\u003Cbr>      \u003Cm:folderids>\u003Cbr>        \u003Ct:distinguishedfolderid id=\"inbox\">\u003Cbr>      \u003C\u002Ft:distinguishedfolderid>\u003C\u002Fm:folderids>\u003Cbr>    \u003C\u002Fm:getfolder>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of decrypting Exchange communication data using Wireshark, describes the approach of logging into EWS using hash, open-source implementation scripts, and records the thought process and development journey.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article \"Penetration Techniques - Pass the Hash with Remote Desktop Protocol,\" we introduced the method of using hash to log into RDP. This article will continue to introduce the method of using hash to log into EWS.\u003C\u002Fp>\u003Cp>We know that using mimikatz's over pass the hash and EWS's login with current credentials can achieve hash-based login to EWS. For related details, refer to \"Exchange Web Service (EWS) Development Guide\"%E5%BC%80%E5%8F%91%E6%8C%87%E5%8D%97)\u003C\u002Fp>\u003Cp>However, the drawback is that it requires administrator privileges and operations on the lsass process, making it impossible to authenticate multiple users simultaneously.\u003C\u002Fp>\u003Cp>Therefore, this article will introduce a more universal method, an open-source implementation script, and document the thought process and development procedure.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Decrypting Exchange communication data\u003C\u002Fli>\u003Cli>The idea of using hash to log into EWS\u003C\u002Fli>\u003Cli>Open-source code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Decrypting Exchange Communication Data\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Exchange uses the TLS protocol by default to encrypt data, and we can only capture encrypted content through Wireshark packet capture, which requires decryption.\u003C\u002Fp>\u003Cp>Here, we introduce methods for capturing plaintext communication data on both Exchange Server and Exchange Client.\u003C\u002Fp>\u003Ch3>1. Method for capturing plaintext communication data on Exchange Server\u003C\u002Fh3>\u003Ch4>(1) Exporting certificate files on Exchange Server\u003C\u002Fh4>\u003Cp>Using mimikatz, the command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe crypto::capi \"crypto::certificates \u002Fsystemstore:local_machine \u002Fstore:my \u002Fexport\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Without using the command crypto::capi, it is not possible to export certificate files with private keys (pfx files).\u003C\u002Fp>\u003Cp>This command will export multiple certificate files, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017381637_0_5ad8049833-1.jpeg\">\u003C\u002Fp>\u003Cp>To find the certificate file used for Exchange communication data, we can use the following method:\u003C\u002Fp>\u003Cp>Access the Exchange login page and locate the corresponding certificate file by checking the certificate's validity period, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017400698_1_3fd6bfd4d2-1.jpeg\">\u003C\u002Fp>\u003Cp>Certificate information can also be obtained via command line, with code available for reference in an open-source project.\u003C\u002Fp>\u003Cp>Test as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017447371_2_054b954646-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Configure Wireshark\u003C\u002Fh4>\u003Cp>Edit -&gt; Preferences...\u003C\u002Fp>\u003Cp>Protocols -&gt; TLS\u003C\u002Fp>\u003Cp>Select RSA keys list\u003C\u002Fp>\u003Cp>Fill in configuration information, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017468998_3_06510e5e1c-1.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Disable ECDH key exchange algorithm\u003C\u002Fh4>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechcommunity.microsoft.com\u002Ft5\u002Fcore-infrastructure-and-security\u002Fdemystifying-schannel\u002Fba-p\u002F259233#\u003C\u002Fp>\u003Cp>CMD command to disable ECDH via registry:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\SCHANNEL\\KeyExchangeAlgorithms\\ECDH \u002Fv Enabled \u002Ft REG_DWORD \u002Fd 0 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After disabling, use SSLCertScan again to obtain certificate information, Key Exchange Algorithm changes from ECDH Ephemeral to RsaKeyX\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017482629_4_6ece131842-1.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the Exchange Server configuration is complete. Capture the data again to obtain plaintext communication data, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017493044_5_62d40d02c5-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Method for Capturing Plaintext Communication Data from Exchange Client\u003C\u002Fh3>\u003Ch4>(1) Add environment variable\u003C\u002Fh4>\u003Cp>Variable name SSLKEYLOGFILE, value is the file path\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017502232_6_c403961a59-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Configure Wireshark\u003C\u002Fh4>\u003Cp>Edit -&gt; Preferences...\u003C\u002Fp>\u003Cp>Protocols -&gt; TLS\u003C\u002Fp>\u003Cp>Set (Pre)-Master-Secret log filename to C:\\test\\sslkey.log\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017507734_7_454316afe6-1.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the Exchange Client configuration is complete\u003C\u002Fp>\u003Cp>Open the Chrome browser, access Exchange, and use Wireshark to obtain plaintext data, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017513552_8_42424b03fd-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Approach to Logging into EWS Using Hash\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Using Mimikatz's over pass the hash and EWS's login with current credentials enables hash-based login to EWS. We captured data on both Exchange Server and Exchange Client, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017519149_9_128e80185a-1.jpeg\">\u003C\u002Fp>\u003Cp>It can be seen that the authentication process here uses NTLM Over HTTP Protocol\u003C\u002Fp>\u003Cp>For details on NTLM Over HTTP Protocol, refer to the previous article 'Penetration Techniques - Obtaining Net-NTLM Hash via HTTP Protocol'\u003C\u002Fp>\u003Cp>Authentication Process:\u003C\u002Fp>\u003Cp>1. The client sends a GET request to the server to obtain webpage content\u003C\u002Fp>\u003Cp>2. Since NTLM authentication is enabled on the server, it returns 401, indicating NTLM authentication is required\u003C\u002Fp>\u003Cp>3. The client initiates NTLM authentication and sends a negotiation message to the server\u003C\u002Fp>\u003Cp>4. Upon receiving the message, the server generates a 16-bit random number (known as Challenge) and sends it back to the client in plaintext\u003C\u002Fp>\u003Cp>5. After receiving the Challenge, the client encrypts it using the input password hash to generate a response, which is then sent to the server\u003C\u002Fp>\u003Cp>6. The server receives the encrypted response from the client, performs the same computation, and compares the results. If they match, subsequent services are provided; otherwise, authentication fails\u003C\u002Fp>\u003Cp>Regarding step 5: 'Encrypt the Challenge using the input password hash'\u003C\u002Fp>\u003Cp>If we directly pass the hash and encrypt the Challenge, we can achieve the same functionality.\u003C\u002Fp>\u003Cp>At this point, we have derived the implementation approach for using hash to log into ews:\u003C\u002Fp>\u003Cp>Simulate NTLM Over HTTP Protocol, directly pass the hash, encrypt the Challenge to generate a response, and send the response to the server.\u003C\u002Fp>\u003Ch2>0x04 Program Implementation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Here, Python is chosen for implementation, with the advantage of directly calling Impacket to implement NTLM Over HTTP Protocol.\u003C\u002Fp>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fdirkjanm\u002FPrivExchange\u002Fblob\u002Fmaster\u002Fprivexchange.py\u003C\u002Fp>\u003Cp>Before running the script, Impacket needs to be installed.\u003C\u002Fp>\u003Cp>Installation method: pip install Impacket\u003C\u002Fp>\u003Cp>My implementation code has been uploaded to GitHub, with the address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code supports verification for both plaintext and NTLM hash.\u003C\u002Fp>\u003Cp>Verifying plaintext, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017523227_10_3af96881d9-1.jpeg\">\u003C\u002Fp>\u003Cp>Verify hash, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017525554_11_74f12950af-1.jpeg\">\u003C\u002Fp>\u003Cp>After successful verification, my code will proceed to send a SOAP command to retrieve inbox information\u003C\u002Fp>\u003Cp>For SOAP command format reference, please see:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fews-operations-in-exchange\u003C\u002Fp>\u003Cp>Note that the SOAP command in the documentation needs format adjustment, otherwise it returns error 500 with the message: An internal server error occurred. The operation failed.\u003C\u002Fp>\u003Cp>Format adjustment example:\u003C\u002Fp>\u003Cp>The SOAP format in https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fgetfolder-operation is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\" \u003Cbr=\"\">   xmlns:t=\"https:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\"&gt;\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cgetfolder xmlns=\"https:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" \u003Cbr=\"\">               xmlns:t=\"https:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\"&gt;\u003Cbr>      \u003Cfoldershape>\u003Cbr>        \u003Ct:baseshape>Default\u003C\u002Ft:baseshape>\u003Cbr>      \u003C\u002Ffoldershape>\u003Cbr>      \u003Cfolderids>\u003Cbr>        \u003Ct:distinguishedfolderid id=\"inbox\">\u003Cbr>      \u003C\u002Ft:distinguishedfolderid>\u003C\u002Ffolderids>\u003Cbr>    \u003C\u002Fgetfolder>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The formatted content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" \u003Cbr=\"\">               xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" \u003Cbr>               xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" \u003Cbr>               xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\"&gt;\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getfolder>\u003Cbr>      \u003Cm:foldershape>\u003Cbr>        \u003Ct:baseshape>Default\u003C\u002Ft:baseshape>\u003Cbr>      \u003C\u002Fm:foldershape>\u003Cbr>      \u003Cm:folderids>\u003Cbr>        \u003Ct:distinguishedfolderid id=\"inbox\">\u003Cbr>      \u003C\u002Ft:distinguishedfolderid>\u003C\u002Fm:folderids>\u003Cbr>    \u003C\u002Fm:getfolder>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of decrypting Exchange communication data using Wireshark, describes the approach of logging into EWS using hash, open-source implementation scripts, and records the thought process and development journey.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1176,"Onedaysec",5,"published","2026-02-02T07:51:00.264Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Pass the Hash with Exchange Web Service: Penetration Techniques","pass the hash, EWS, Exchange Web Service, penetration testing, NTLM authentication, hash login, mimikatz, Wireshark decryption",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],430,429,428,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.409Z","2026-07-23T16:01:34.170Z","draft","2026-07-23T16:06:11.185Z"]