[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f64RIV35VrRdpGVp4cWCisRcq8k9JdecBGOh5kqQETuQ":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},961,"What are the key authentication and encoding details to consider when writing a Python Exchange PowerShell client?","Kerberos authentication requires the hostname (lowercase) and a full FQDN – IPs are not supported. The HTTP headers must include `Accept-Encoding: identity`. Both sent and received data are encoded (e.g., base64). After the initial Kerberos step, subsequent requests carry normal command payloads. These nuances are crucial for interoperability and are detailed in [Penetration Technique: Remote Access to Exchange PowerShell](\u002Fnews\u002Fpenetration-technique-remote-access-to-exchange-powershell) and the Python implementation article.","\u003Cp>Kerberos authentication requires the hostname (lowercase) and a full FQDN – IPs are not supported. The HTTP headers must include `Accept-Encoding: identity`. Both sent and received data are encoded (e.g., base64). After the initial Kerberos step, subsequent requests carry normal command payloads. These nuances are crucial for interoperability and are detailed in [Penetration Technique: Remote Access to Exchange PowerShell](\u002Fnews\u002Fpenetration-technique-remote-access-to-exchange-powershell) and the Python implementation article.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-technique-pythonimplementation-of-exchange-powershell\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-key-authentication-and-encoding-details-to-consider-when-writing-a--1777481195008","Kerberos, data encoding, authentication, FQDN, Exchange PowerShell",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},234,"Penetration Technique: Python Implementation of Exchange PowerShell","penetration-technique-pythonimplementation-of-exchange-powershell","Learn to remotely execute Exchange PowerShell commands via Python, exploit TabShell, use pypsrp, Kerberos auth, and analyze SSRF in Exchange server penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>Penetration Technique: Python Implementation of Exchange PowerShell\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>0x00 Preface\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Remote execution of Exchange PowerShell commands can be achieved by establishing a PowerShell session via PowerShell. However, in penetration testing, we need to avoid using PowerShell as much as possible and instead implement it through programs. This article will introduce the details of remotely executing Exchange PowerShell commands via Python and share insights on exploiting TabShell using Python.\u003C\u002Fp>\u003Cp>\u003Cstrong>0x01 Introduction\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This document will cover the following content:\u003C\u002Fp>\u003Cp>Practical Methods for Executing Exchange PowerShell Commands\u003C\u002Fp>\u003Cp>Development Details\u003C\u002Fp>\u003Cp>TabShell Exploitation Details\u003C\u002Fp>\u003Cp>\u003Cstrong>0x02 Practical Methods for Executing Exchange PowerShell Commands\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Use PowerShell to connect to the Exchange server and execute Exchange PowerShell commands\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Command Example:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fuploads\u002Fdocx_image_1769397689086_0_49b91adc26.png\">\u003C\u002Fp>\u003Cp>Note the following points:\u003C\u002Fp>\u003Cp>Must be executed on a domain-joined host\u003C\u002Fp>\u003Cp>Requires FQDN; IP is not supported\u003C\u002Fp>\u003Cp>The connection URL can use HTTP or HTTPS\u003C\u002Fp>\u003Cp>Authentication method can be Basic or Kerberos\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Use Python to connect to the Exchange server and execute Exchange PowerShell commands\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>We need to use pypsrp here\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fuploads\u002Fdocx_image_1769397697677_1_21471659d1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>0x03 Development Details\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>We need to understand the specific communication format here. The method I adopted is to use pypsrp, enable debug information, and check the specific data format sent\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Enable debug information\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Write the debug information to a file; the code is as follows:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fuploads\u002Fdocx_image_1769397702576_2_f1755de56c.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Add debug output content\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Modify the file pypsrp\u002Fwsman.py and add debug output information in the def send(self, message: bytes) method\u003C\u002Fp>\u003Cp>Specific code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjborean93\u002Fpypsrp\u002Fblob\u002Fmaster\u002Fsrc\u002Fpypsrp\u002Fwsman.py#L834, add the code:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fuploads\u002Fdocx_image_1769397706949_3_552b979c2f.png\">https:\u002F\u002Fgithub.com\u002Fjborean93\u002Fpypsrp\u002Fblob\u002Fmaster\u002Fsrc\u002Fpypsrp\u002Fwsman.py#L841, add the code:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fuploads\u002Fdocx_image_1769397711445_4_68eb9de0c7.png\">The output result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fuploads\u002Fdocx_image_1769397715310_5_d354ebecdc.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Data Packet Data Structure\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can refer to the previous article 《Penetration Technique – Remote Access to Exchange Powershell》\u003C\u002Fp>\u003Cp>After comparative analysis, the following details need to be noted when writing the program:\u003C\u002Fp>\u003Cp>(1) Actual situation of Kerberos authentication\u003C\u002Fp>\u003Cp>Sample code:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fuploads\u002Fdocx_image_1769397723631_6_8dfaade26b.png\">\u003C\u002Fp>\u003Cp>(2) Communication data format\u003C\u002Fp>\u003Cp>Type is POST\u003C\u002Fp>\u003Cp>The header needs to include: 'Accept-Encoding': 'identity'\u003C\u002Fp>\u003Cp>(3) Authentication process\u003C\u002Fp>\u003Cp>First, Kerberos authentication needs to be performed, which returns a length of 0\u003C\u002Fp>\u003Cp>Send data again, communicate, and return normal content\u003C\u002Fp>\u003Cp>(4) Data encoding\u003C\u002Fp>\u003Cp>Both sent and received data are encoded\u003C\u002Fp>\u003Cp>Sample code for the sending process:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fuploads\u002Fdocx_image_1769397728832_7_f8e5b98593.png\">\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>Hostname must be lowercase\u003C\u002Fp>\u003Cp>Decoding sample code for the receiving process:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fuploads\u002Fdocx_image_1769397733949_8_fdadddc4ee.png\">The complete sample code is shown below:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fuploads\u002Fdocx_image_1769397738414_9_4b4d8eb5c7.png\">\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fuploads\u002Fdocx_image_1769397743865_10_50b328ed16.png\">The output result of the complete code is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fuploads\u002Fdocx_image_1769397749742_11_840a9c2a7f.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>0x04 TabShell Exploitation Details\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The public POC of TabShell uses PowerShell to connect to the Exchange Server and execute specially constructed Exchange PowerShell commands. To facilitate the analysis of intermediate communication data, the following methods can be used to intercept the intermediate traffic:\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Build a local proxy server via Flask\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can refer to the previous article \"ProxyShell Exploitation Analysis 3 – Adding Users and File Writing\" for the method\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Implement SSRF via Flask\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For the SSRF vulnerability, you can choose CVE-2022-41040 or CVE-2022-41080\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Output intermediate communication data in Flask\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Key code example:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fuploads\u002Fdocx_image_1769397753684_12_e3967e97a7.png\">Based on the communication data, we can easily write modern Python code for TabShell; the output result of the complete code is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fuploads\u002Fdocx_image_1769397758938_13_3434039cf0.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>0x05 Summary\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This document introduces the details of remotely executing Exchange PowerShell commands using Python and shares the experience of implementing TabShell with Python\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Cp>\u003Cstrong>Penetration Technique: Python Implementation of Exchange PowerShell\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>0x00 Preface\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Remote execution of Exchange PowerShell commands can be achieved by establishing a PowerShell session via PowerShell. However, in penetration testing, we need to avoid using PowerShell as much as possible and instead implement it through programs. This article will introduce the details of remotely executing Exchange PowerShell commands via Python and share insights on exploiting TabShell using Python.\u003C\u002Fp>\u003Cp>\u003Cstrong>0x01 Introduction\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This document will cover the following content:\u003C\u002Fp>\u003Cp>Practical Methods for Executing Exchange PowerShell Commands\u003C\u002Fp>\u003Cp>Development Details\u003C\u002Fp>\u003Cp>TabShell Exploitation Details\u003C\u002Fp>\u003Cp>\u003Cstrong>0x02 Practical Methods for Executing Exchange PowerShell Commands\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Use PowerShell to connect to the Exchange server and execute Exchange PowerShell commands\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Command Example:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397689086_0_49b91adc26-1.png\">\u003C\u002Fp>\u003Cp>Note the following points:\u003C\u002Fp>\u003Cp>Must be executed on a domain-joined host\u003C\u002Fp>\u003Cp>Requires FQDN; IP is not supported\u003C\u002Fp>\u003Cp>The connection URL can use HTTP or HTTPS\u003C\u002Fp>\u003Cp>Authentication method can be Basic or Kerberos\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Use Python to connect to the Exchange server and execute Exchange PowerShell commands\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>We need to use pypsrp here\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397697677_1_21471659d1-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>0x03 Development Details\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>We need to understand the specific communication format here. The method I adopted is to use pypsrp, enable debug information, and check the specific data format sent\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Enable debug information\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Write the debug information to a file; the code is as follows:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397702576_2_f1755de56c-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Add debug output content\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Modify the file pypsrp\u002Fwsman.py and add debug output information in the def send(self, message: bytes) method\u003C\u002Fp>\u003Cp>Specific code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjborean93\u002Fpypsrp\u002Fblob\u002Fmaster\u002Fsrc\u002Fpypsrp\u002Fwsman.py#L834, add the code:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397706949_3_552b979c2f-1.png\">https:\u002F\u002Fgithub.com\u002Fjborean93\u002Fpypsrp\u002Fblob\u002Fmaster\u002Fsrc\u002Fpypsrp\u002Fwsman.py#L841, add the code:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397711445_4_68eb9de0c7-1.png\">The output result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397715310_5_d354ebecdc-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Data Packet Data Structure\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can refer to the previous article 《Penetration Technique – Remote Access to Exchange Powershell》\u003C\u002Fp>\u003Cp>After comparative analysis, the following details need to be noted when writing the program:\u003C\u002Fp>\u003Cp>(1) Actual situation of Kerberos authentication\u003C\u002Fp>\u003Cp>Sample code:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397723631_6_8dfaade26b-1.png\">\u003C\u002Fp>\u003Cp>(2) Communication data format\u003C\u002Fp>\u003Cp>Type is POST\u003C\u002Fp>\u003Cp>The header needs to include: 'Accept-Encoding': 'identity'\u003C\u002Fp>\u003Cp>(3) Authentication process\u003C\u002Fp>\u003Cp>First, Kerberos authentication needs to be performed, which returns a length of 0\u003C\u002Fp>\u003Cp>Send data again, communicate, and return normal content\u003C\u002Fp>\u003Cp>(4) Data encoding\u003C\u002Fp>\u003Cp>Both sent and received data are encoded\u003C\u002Fp>\u003Cp>Sample code for the sending process:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397728832_7_f8e5b98593-1.png\">\u003C\u002Fp>\u003Cp>Note:\u003C\u002Fp>\u003Cp>Hostname must be lowercase\u003C\u002Fp>\u003Cp>Decoding sample code for the receiving process:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397733949_8_fdadddc4ee-1.png\">The complete sample code is shown below:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397738414_9_4b4d8eb5c7-1.png\">\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397743865_10_50b328ed16-1.png\">The output result of the complete code is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397749742_11_840a9c2a7f-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>0x04 TabShell Exploitation Details\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The public POC of TabShell uses PowerShell to connect to the Exchange Server and execute specially constructed Exchange PowerShell commands. To facilitate the analysis of intermediate communication data, the following methods can be used to intercept the intermediate traffic:\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Build a local proxy server via Flask\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can refer to the previous article \"ProxyShell Exploitation Analysis 3 – Adding Users and File Writing\" for the method\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Implement SSRF via Flask\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For the SSRF vulnerability, you can choose CVE-2022-41040 or CVE-2022-41080\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Output intermediate communication data in Flask\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Key code example:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397753684_12_e3967e97a7-1.png\">Based on the communication data, we can easily write modern Python code for TabShell; the output result of the complete code is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"【技术原创】渗透技巧——Exchange Powershell的Python实现\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1769397758938_13_3434039cf0-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>0x05 Summary\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This document introduces the details of remotely executing Exchange PowerShell commands using Python and shares the experience of implementing TabShell with Python\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",531,"Onedaysec",3,"published","2026-02-02T07:25:20.010Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Python Exchange PowerShell & TabShell Exploitation Guide","Penetration Technique, Python Exchange PowerShell, TabShell Exploitation, Remote Exchange PowerShell Execution, pypsrp, Kerberos Authentication, Exchange Server Penetration, SSRF, CVE-2022-41040, CVE-2022-41080",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46,47],960,959,958,957,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.557Z","2026-07-23T16:02:20.426Z","draft","2026-07-23T16:15:47.670Z"]