[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLlqcYY_4D_9VzfP7OkD_kGLIT2JGAjp-8bUaP6jZJ-Y":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},399,"What are the main methods to extract the Exchange GlobalAddressList during penetration testing, and which one requires only an NTLM hash instead of plaintext credentials?","The main methods include Outlook Web Access (OWA), Exchange Web Service (EWS) using FindPeople or ResolveName operations, Outlook client protocols such as MAPI over HTTP or RPC over HTTP, the Offline Address Book (OAB), and LDAP queries against the domain controller. The EWS method also supports using an NTLM hash (via [Pass the Hash with Exchange Web Service](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-exchange-web-service)) in tools like the ewsM Python script, whereas most other methods require plaintext passwords.","\u003Cp>The main methods include Outlook Web Access (OWA), Exchange Web Service (EWS) using FindPeople or ResolveName operations, Outlook client protocols such as MAPI over HTTP or RPC over HTTP, the Offline Address Book (OAB), and LDAP queries against the domain controller. The EWS method also supports using an NTLM hash (via [Pass the Hash with Exchange Web Service](\u002Fnews\u002Fpenetration-techniques-pass-the-hash-with-exchange-web-service)) in tools like the ewsM Python script, whereas most other methods require plaintext passwords.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-methods-to-obtain-exchange-globaladdresslist\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-main-methods-to-extract-the-exchange-globaladdresslist-during-penet-1777483798862","Exchange GlobalAddressList, OWA, EWS, MAPI over HTTP, RPC over HTTP, Offline Address Book, LDAP, NTLM hash, penetration testing",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},100,"Penetration Techniques - Methods to Obtain Exchange GlobalAddressList","penetration-techniques-methods-to-obtain-exchange-globaladdresslist","Learn methods to obtain Exchange GlobalAddressList in penetration testing, including OWA, EWS, MAPI over HTTP, and OAB techniques for extracting email addresses.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The Exchange GlobalAddressList contains the email addresses of all mailbox users within the Exchange organization. By obtaining the credentials of any mailbox user in the Exchange organization, one can export the email addresses of other mailbox users through the GlobalAddressList.\u003C\u002Fp>\u003Cp>This article will introduce common methods for obtaining the Exchange GlobalAddressList under different conditions during penetration testing, share details of program implementation, and finally discuss methods to disable the GlobalAddressList.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Methods to obtain the Exchange GlobalAddressList\u003C\u002Fli>\u003Cli>Program implementation\u003C\u002Fli>\u003Cli>Methods to disable the GlobalAddressList\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods to Obtain the Exchange GlobalAddressList\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Through Outlook Web Access (OWA)\u003C\u002Fh3>\u003Cp>Requires obtaining the plaintext password of a mail user. After logging into OWA, select Contacts -&gt; All Users\u003C\u002Fp>\u003Ch3>2. Via Exchange Web Service (EWS)\u003C\u002Fh3>\u003Cp>For Exchange 2013 and later versions, the FindPeople operation can be used\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Ffindpeople-operation?redirectedfrom=MSDN\u003C\u002Fp>\u003Cp>It should be noted that search criteria must be specified when using the FindPeople operation; it cannot directly retrieve all results using wildcards\u003C\u002Fp>\u003Cp>Alternative workaround:\u003C\u002Fp>\u003Cp>Iterate through the 26 letters a-z as search criteria, which can cover all results\u003C\u002Fp>\u003Cp>For Exchange 2010 and earlier versions, only the ResolveName operation can be used\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fdotnet\u002Fapi\u002Fmicrosoft.exchange.webservices.data.exchangeservice.resolvename?redirectedfrom=MSDN&amp;view=exchange-ews-api\u003C\u002Fp>\u003Cp>It should be noted that the ResolveName operation can only retrieve a maximum of 100 results at a time. If the number of mailbox users in the Global Address List exceeds 100, the complete results cannot be obtained directly\u003C\u002Fp>\u003Cp>Alternative workaround:\u003C\u002Fp>\u003Cp>When using the ResolveName operation, include search criteria to ensure each query returns fewer than 100 results, then cover all results through multiple searches\u003C\u002Fp>\u003Cp>Commonly used method:\u003C\u002Fp>\u003Cp>Use search criteria consisting of any combination of two letters, such as aa, ab, ac....zz, for a total of 26*26=676 searches, which generally covers all results\u003C\u002Fp>\u003Ch3>3. Protocols used through Outlook client (MAPI OVER HTTP and RPC over HTTP)\u003C\u002Fh3>\u003Cp>Log in as a user, select Contacts -&gt; Address Book\u003C\u002Fp>\u003Cp>Protocols commonly used by Outlook client are RPC, RPC over HTTP (also known as Outlook Anywhere), and MAPI over HTTP\u003C\u002Fp>\u003Cp>Using ruler can read GlobalAddressList via MAPI OVER HTTP (RPC over HTTP is not currently supported)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>MAPI over HTTP is a new transport protocol implemented in Exchange Server 2013 Service Pack 1 (SP1), used to replace RPC OVER HTTP (also known as Outlook Anywhere)\u003C\u002Fp>\u003Cp>Exchange 2013 does not enable MAPI OVER HTTP by default, instead uses RPC OVER HTTP, requiring manual activation\u003C\u002Fp>\u003Cp>Exchange 2016 enables MAPI OVER HTTP by default\u003C\u002Fp>\u003Cp>Reading GlobalAddressList via RPC over HTTP can be done using ptswarm's Exchanger.py\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fswarm.ptsecurity.com\u002Fattacking-ms-exchange-web-interfaces\u002F\u003C\u002Fp>\u003Cp>Process is as follows:\u003C\u002Fp>\u003Ch4>(1) List AddressList\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python exchanger.py 192.168.1.1\u002Ftest1:DomainUser123!@test.com nspi list-tables\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017325140_0_1ed1dcffcb.jpeg\">\u003C\u002Fp>\u003Cp>From the figure, it can be obtained that the guid corresponding to All Users is 5cb80229-e2b4-4447-b224-dc2c12098835\u003C\u002Fp>\u003Ch4>(2) Read AddressList\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python exchanger.py 192.168.1.1\u002Ftest1:DomainUser123!@test.com nspi dump-tables -guid 5cb80229-e2b4-4447-b224-dc2c12098835\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017376079_1_ec8a566fbc.jpeg\">\u003C\u002Fp>\u003Ch3>4. Via Offline Address Book (OAB)\u003C\u002Fh3>\u003Cp>The process is as follows:\u003C\u002Fp>\u003Ch4>(1) Read Autodiscover configuration information\u003C\u002Fh4>\u003Cp>URL to access: https:\u002F\u002F\u003Cdomain>\u002Fautodiscover\u002Fautodiscover.xml\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A specific POST request needs to be sent. For details, refer to the article 'Penetration Basics—Using Exchange Autodiscover'\u003C\u002Fp>\u003Cp>Obtain the OABUrl from the configuration information\u003C\u002Fp>\u003Ch4>(2) Read OAB file list\u003C\u002Fh4>\u003Cp>Accessed URL: OABUrl\u002Foab.xml\u003C\u002Fp>\u003Cp>The returned result includes a list of multiple OAB files, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017396478_2_3be1a4c235.jpeg\">\u003C\u002Fp>\u003Cp>Find the lzx file name corresponding to the Default Global Address List. The lzx file name is 4667c322-5c08-4cda-844a-253ff36b4a6a-data-5.lzx\u003C\u002Fp>\u003Ch4>(3) Download the lzx file\u003C\u002Fh4>\u003Cp>Accessed URL: OABUrl\u002Fxx.lzx\u003C\u002Fp>\u003Cp>Corresponding to the example above, the download URL for the lzx file is: https:\u002F\u002F192.168.1.1\u002FOAB\u002F9e3fa457-ebf1-40e4-b265-21d09a62872b\u002F4667c322-5c08-4cda-844a-253ff36b4a6a-data-5.lzx\u003C\u002Fp>\u003Ch4>(4) Decode the lzx file to restore the Default Global Address List\u003C\u002Fh4>\u003Cp>The tool oabextract is required here\u003C\u002Fp>\u003Cp>Download and installation are necessary\u003C\u002Fp>\u003Cp>Download link for a pre-compiled version ready to use directly on Kali: http:\u002F\u002Fx2100.icecube.wisc.edu\u002Fdownloads\u002Fpython\u002Fpython2.6.Linux-x86_64.gcc-4.4.4\u002Fbin\u002Foabextract\u003C\u002Fp>\u003Cp>Example command to convert the lzx file to an oab file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>oabextract 4667c322-5c08-4cda-844a-253ff36b4a6a-data-5.lzx gal.oab\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example command to extract the GAL:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>strings gal.oab|grep SMTP\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017444523_3_ebee438a71.jpeg\">\u003C\u002Fp>\u003Ch3>5. Via LDAP\u003C\u002Fh3>\u003Cp>Requires access to the domain controller's LDAP service (port 389)\u003C\u002Fp>\u003Cp>Typically, there is a correspondence between Exchange mailbox users and domain users, so information about Exchange mailbox users can be obtained based on domain user information\u003C\u002Fp>\u003Ch4>(1) Querying from outside the domain\u003C\u002Fh4>\u003Cp>Requires obtaining the plaintext password of a domain user\u003C\u002Fp>\u003Cp>Example command for Kali system to retrieve all user email addresses using ldapsearch:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" |grep mail:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017467797_4_dfebe91df1.jpeg\">\u003C\u002Fp>\u003Cp>Example command for Windows system to retrieve all user email addresses using PowerView:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Get-NetUser -Domain test.com -DomainController 192.168.1.1 -ADSpath \"LDAP:\u002F\u002FDC=test,DC=com\" -Credential $cred | fl mail\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017481463_5_baf9491a34.jpeg\">\u003C\u002Fp>\u003Cp>Windows system implementation via C#:\u003C\u002Fp>\u003Cp>By invoking the namespace System.DirectoryServices, the same operation can be easily achieved. The code has been uploaded to GitHub, with the address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017491670_6_374494e0b1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Querying from within the domain\u003C\u002Fh4>\u003Cp>All methods for querying from outside the domain are applicable, and domain user credentials are not required at this time\u003C\u002Fp>\u003Cp>You can also query via Exchange Management Shell after connecting to the Exchange server using PSSession\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$User = \"test\\administrator\"\u003Cbr>$Pass = ConvertTo-SecureString -AsPlainText DomainAdmin123! -Force\u003Cbr>$Credential = New-Object System.Management.Automation.PSCredential -ArgumentList $User,$Pass\u003Cbr>$Session = New-PSSession -ConfigurationName Microsoft.Exchange -ConnectionUri http:\u002F\u002FExchange01.test.com\u002FPowerShell\u002F -Authentication Kerberos -Credential $Credential\u003Cbr>Import-PSSession $Session -AllowClobber\u003Cbr>Get-Mailbox|fl PrimarySmtpAddress\u003Cbr>Remove-PSSession $Session\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017501447_7_2c63a0849c.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Implementation code for obtaining GlobalAddressList via Exchange Web Service (EWS)\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. PowerShell\u003C\u002Fh3>\u003Cp>Requires plaintext password\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fdafthack\u002FMailSniper\u003C\u002Fp>\u003Cp>Requires PowerShell version 3.0\u003C\u002Fp>\u003Cp>Supports FindPeople operation and ResolveName operation\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The FindPeople operation is implemented via OWA\u003C\u002Fp>\u003Cp>The ResolveName operation is implemented via EWS\u003C\u002Fp>\u003Ch3>2. Python\u003C\u002Fh3>\u003Cp>Requires plaintext password or NTLM hash\u003C\u002Fp>\u003Ch4>(1) FindPeople operation\u003C\u002Fh4>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Ffindpeople-operation?redirectedfrom=MSDN\u003C\u002Fp>\u003Cp>Only available in Exchange Server 2013 or later versions\u003C\u002Fp>\u003Cp>XML format example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>      \u003Cm:findpeople>\u003Cbr>         \u003Cm:indexedpageitemview basepoint=\"Beginning\" maxentriesreturned=\"1000\" offset=\"0\">\u003Cbr>         \u003Cm:parentfolderid>\u003Cbr>            \u003Ct:distinguishedfolderid id=\"directory\">\u003Cbr>         \u003C\u002Ft:distinguishedfolderid>\u003C\u002Fm:parentfolderid>\u003Cbr>         \u003Cm:querystring>test\u003C\u002Fm:querystring>\u003Cbr>      \u003C\u002Fm:indexedpageitemview>\u003C\u002Fm:findpeople>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Search string test, specifying maximum query result count of 1000\u003C\u002Fp>\u003Cp>To cover all results, the search string needs to iterate through 26 letters a-z, with deduplication applied after obtaining returned results\u003C\u002Fp>\u003Cp>Complete code can refer to the findallpeople function I added in ewsManage\u003C\u002Fp>\u003Ch4>(2) ResolveName operation\u003C\u002Fh4>\u003Cp>XML format example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:resolvenames returnfullcontactdata=\"false\" searchscope=\"ContactsActiveDirectory\">\u003Cbr>      \u003Cm:unresolvedentry>test\u003C\u002Fm:unresolvedentry>\u003Cbr>    \u003C\u002Fm:resolvenames>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Search string test, where the maximum number of query results returned is 100.\u003C\u002Fp>\u003Cp>To cover all results, the search criteria are combinations of any two letters, such as aa, ab, ac....zz, totaling 26*26=676 searches. Generally, this can cover all results, and deduplication is performed after obtaining the returned results.\u003C\u002Fp>\u003Cp>It is important to note that if the returned result for a search condition is 100, it indicates that the result for this condition may be incomplete (actual count greater than 100, only 100 obtained). Further subdivision is required, involving a third-level traversal. The returned results can be obtained by reading the TotalItemsInView item in the response content.\u003C\u002Fp>\u003Cp>For the complete code, refer to the resolveallname feature I added in ewsManage.\u003C\u002Fp>\u003Ch2>0x04 Methods to Disable GlobalAddressList\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>You can choose to specify whether a user is hidden in the Global Address List.\u003C\u002Fp>\u003Ch3>1. Via Exchange Admin Center (EAC)\u003C\u002Fh3>\u003Cp>Log in to the Exchange Control Panel (ECP) using an Exchange administrator account.\u003C\u002Fp>\u003Cp>Select the specified user, choose General, check Hide from address lists, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017507556_8_9de0bac2df.jpeg\">\u003C\u002Fp>\u003Ch3>2. Via Exchange Management Shell\u003C\u002Fh3>\u003Cp>Command to hide a specified user:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-MailContact -HiddenFromAddressListsEnabled $true -Identity test1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command to hide all users:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MailContact | Set-MailContact -HiddenFromAddressListsEnabled $true\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces common methods for obtaining the Exchange Global Address List under different conditions, describes writing programs to export the Global Address List via EWS's FindPeople operation and ResolveName operation respectively, and finally explains how to disable the Global Address List.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The Exchange GlobalAddressList contains the email addresses of all mailbox users within the Exchange organization. By obtaining the credentials of any mailbox user in the Exchange organization, one can export the email addresses of other mailbox users through the GlobalAddressList.\u003C\u002Fp>\u003Cp>This article will introduce common methods for obtaining the Exchange GlobalAddressList under different conditions during penetration testing, share details of program implementation, and finally discuss methods to disable the GlobalAddressList.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Methods to obtain the Exchange GlobalAddressList\u003C\u002Fli>\u003Cli>Program implementation\u003C\u002Fli>\u003Cli>Methods to disable the GlobalAddressList\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods to Obtain the Exchange GlobalAddressList\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Through Outlook Web Access (OWA)\u003C\u002Fh3>\u003Cp>Requires obtaining the plaintext password of a mail user. After logging into OWA, select Contacts -&gt; All Users\u003C\u002Fp>\u003Ch3>2. Via Exchange Web Service (EWS)\u003C\u002Fh3>\u003Cp>For Exchange 2013 and later versions, the FindPeople operation can be used\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Ffindpeople-operation?redirectedfrom=MSDN\u003C\u002Fp>\u003Cp>It should be noted that search criteria must be specified when using the FindPeople operation; it cannot directly retrieve all results using wildcards\u003C\u002Fp>\u003Cp>Alternative workaround:\u003C\u002Fp>\u003Cp>Iterate through the 26 letters a-z as search criteria, which can cover all results\u003C\u002Fp>\u003Cp>For Exchange 2010 and earlier versions, only the ResolveName operation can be used\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fdotnet\u002Fapi\u002Fmicrosoft.exchange.webservices.data.exchangeservice.resolvename?redirectedfrom=MSDN&amp;view=exchange-ews-api\u003C\u002Fp>\u003Cp>It should be noted that the ResolveName operation can only retrieve a maximum of 100 results at a time. If the number of mailbox users in the Global Address List exceeds 100, the complete results cannot be obtained directly\u003C\u002Fp>\u003Cp>Alternative workaround:\u003C\u002Fp>\u003Cp>When using the ResolveName operation, include search criteria to ensure each query returns fewer than 100 results, then cover all results through multiple searches\u003C\u002Fp>\u003Cp>Commonly used method:\u003C\u002Fp>\u003Cp>Use search criteria consisting of any combination of two letters, such as aa, ab, ac....zz, for a total of 26*26=676 searches, which generally covers all results\u003C\u002Fp>\u003Ch3>3. Protocols used through Outlook client (MAPI OVER HTTP and RPC over HTTP)\u003C\u002Fh3>\u003Cp>Log in as a user, select Contacts -&gt; Address Book\u003C\u002Fp>\u003Cp>Protocols commonly used by Outlook client are RPC, RPC over HTTP (also known as Outlook Anywhere), and MAPI over HTTP\u003C\u002Fp>\u003Cp>Using ruler can read GlobalAddressList via MAPI OVER HTTP (RPC over HTTP is not currently supported)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>MAPI over HTTP is a new transport protocol implemented in Exchange Server 2013 Service Pack 1 (SP1), used to replace RPC OVER HTTP (also known as Outlook Anywhere)\u003C\u002Fp>\u003Cp>Exchange 2013 does not enable MAPI OVER HTTP by default, instead uses RPC OVER HTTP, requiring manual activation\u003C\u002Fp>\u003Cp>Exchange 2016 enables MAPI OVER HTTP by default\u003C\u002Fp>\u003Cp>Reading GlobalAddressList via RPC over HTTP can be done using ptswarm's Exchanger.py\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fswarm.ptsecurity.com\u002Fattacking-ms-exchange-web-interfaces\u002F\u003C\u002Fp>\u003Cp>Process is as follows:\u003C\u002Fp>\u003Ch4>(1) List AddressList\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python exchanger.py 192.168.1.1\u002Ftest1:DomainUser123!@test.com nspi list-tables\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017325140_0_1ed1dcffcb-1.jpeg\">\u003C\u002Fp>\u003Cp>From the figure, it can be obtained that the guid corresponding to All Users is 5cb80229-e2b4-4447-b224-dc2c12098835\u003C\u002Fp>\u003Ch4>(2) Read AddressList\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python exchanger.py 192.168.1.1\u002Ftest1:DomainUser123!@test.com nspi dump-tables -guid 5cb80229-e2b4-4447-b224-dc2c12098835\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017376079_1_ec8a566fbc-1.jpeg\">\u003C\u002Fp>\u003Ch3>4. Via Offline Address Book (OAB)\u003C\u002Fh3>\u003Cp>The process is as follows:\u003C\u002Fp>\u003Ch4>(1) Read Autodiscover configuration information\u003C\u002Fh4>\u003Cp>URL to access: https:\u002F\u002F\u003Cdomain>\u002Fautodiscover\u002Fautodiscover.xml\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A specific POST request needs to be sent. For details, refer to the article 'Penetration Basics—Using Exchange Autodiscover'\u003C\u002Fp>\u003Cp>Obtain the OABUrl from the configuration information\u003C\u002Fp>\u003Ch4>(2) Read OAB file list\u003C\u002Fh4>\u003Cp>Accessed URL: OABUrl\u002Foab.xml\u003C\u002Fp>\u003Cp>The returned result includes a list of multiple OAB files, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017396478_2_3be1a4c235-1.jpeg\">\u003C\u002Fp>\u003Cp>Find the lzx file name corresponding to the Default Global Address List. The lzx file name is 4667c322-5c08-4cda-844a-253ff36b4a6a-data-5.lzx\u003C\u002Fp>\u003Ch4>(3) Download the lzx file\u003C\u002Fh4>\u003Cp>Accessed URL: OABUrl\u002Fxx.lzx\u003C\u002Fp>\u003Cp>Corresponding to the example above, the download URL for the lzx file is: https:\u002F\u002F192.168.1.1\u002FOAB\u002F9e3fa457-ebf1-40e4-b265-21d09a62872b\u002F4667c322-5c08-4cda-844a-253ff36b4a6a-data-5.lzx\u003C\u002Fp>\u003Ch4>(4) Decode the lzx file to restore the Default Global Address List\u003C\u002Fh4>\u003Cp>The tool oabextract is required here\u003C\u002Fp>\u003Cp>Download and installation are necessary\u003C\u002Fp>\u003Cp>Download link for a pre-compiled version ready to use directly on Kali: http:\u002F\u002Fx2100.icecube.wisc.edu\u002Fdownloads\u002Fpython\u002Fpython2.6.Linux-x86_64.gcc-4.4.4\u002Fbin\u002Foabextract\u003C\u002Fp>\u003Cp>Example command to convert the lzx file to an oab file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>oabextract 4667c322-5c08-4cda-844a-253ff36b4a6a-data-5.lzx gal.oab\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example command to extract the GAL:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>strings gal.oab|grep SMTP\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017444523_3_ebee438a71-1.jpeg\">\u003C\u002Fp>\u003Ch3>5. Via LDAP\u003C\u002Fh3>\u003Cp>Requires access to the domain controller's LDAP service (port 389)\u003C\u002Fp>\u003Cp>Typically, there is a correspondence between Exchange mailbox users and domain users, so information about Exchange mailbox users can be obtained based on domain user information\u003C\u002Fp>\u003Ch4>(1) Querying from outside the domain\u003C\u002Fh4>\u003Cp>Requires obtaining the plaintext password of a domain user\u003C\u002Fp>\u003Cp>Example command for Kali system to retrieve all user email addresses using ldapsearch:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainUser123! -b \"DC=test,DC=com\" |grep mail:\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017467797_4_dfebe91df1-1.jpeg\">\u003C\u002Fp>\u003Cp>Example command for Windows system to retrieve all user email addresses using PowerView:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"testa\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainUser123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)        \u003Cbr>Get-NetUser -Domain test.com -DomainController 192.168.1.1 -ADSpath \"LDAP:\u002F\u002FDC=test,DC=com\" -Credential $cred | fl mail\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017481463_5_baf9491a34-1.jpeg\">\u003C\u002Fp>\u003Cp>Windows system implementation via C#:\u003C\u002Fp>\u003Cp>By invoking the namespace System.DirectoryServices, the same operation can be easily achieved. The code has been uploaded to GitHub, with the address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017491670_6_374494e0b1-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Querying from within the domain\u003C\u002Fh4>\u003Cp>All methods for querying from outside the domain are applicable, and domain user credentials are not required at this time\u003C\u002Fp>\u003Cp>You can also query via Exchange Management Shell after connecting to the Exchange server using PSSession\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$User = \"test\\administrator\"\u003Cbr>$Pass = ConvertTo-SecureString -AsPlainText DomainAdmin123! -Force\u003Cbr>$Credential = New-Object System.Management.Automation.PSCredential -ArgumentList $User,$Pass\u003Cbr>$Session = New-PSSession -ConfigurationName Microsoft.Exchange -ConnectionUri http:\u002F\u002FExchange01.test.com\u002FPowerShell\u002F -Authentication Kerberos -Credential $Credential\u003Cbr>Import-PSSession $Session -AllowClobber\u003Cbr>Get-Mailbox|fl PrimarySmtpAddress\u003Cbr>Remove-PSSession $Session\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017501447_7_2c63a0849c-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Implementation code for obtaining GlobalAddressList via Exchange Web Service (EWS)\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. PowerShell\u003C\u002Fh3>\u003Cp>Requires plaintext password\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fdafthack\u002FMailSniper\u003C\u002Fp>\u003Cp>Requires PowerShell version 3.0\u003C\u002Fp>\u003Cp>Supports FindPeople operation and ResolveName operation\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The FindPeople operation is implemented via OWA\u003C\u002Fp>\u003Cp>The ResolveName operation is implemented via EWS\u003C\u002Fp>\u003Ch3>2. Python\u003C\u002Fh3>\u003Cp>Requires plaintext password or NTLM hash\u003C\u002Fp>\u003Ch4>(1) FindPeople operation\u003C\u002Fh4>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Ffindpeople-operation?redirectedfrom=MSDN\u003C\u002Fp>\u003Cp>Only available in Exchange Server 2013 or later versions\u003C\u002Fp>\u003Cp>XML format example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>      \u003Cm:findpeople>\u003Cbr>         \u003Cm:indexedpageitemview basepoint=\"Beginning\" maxentriesreturned=\"1000\" offset=\"0\">\u003Cbr>         \u003Cm:parentfolderid>\u003Cbr>            \u003Ct:distinguishedfolderid id=\"directory\">\u003Cbr>         \u003C\u002Ft:distinguishedfolderid>\u003C\u002Fm:parentfolderid>\u003Cbr>         \u003Cm:querystring>test\u003C\u002Fm:querystring>\u003Cbr>      \u003C\u002Fm:indexedpageitemview>\u003C\u002Fm:findpeople>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Search string test, specifying maximum query result count of 1000\u003C\u002Fp>\u003Cp>To cover all results, the search string needs to iterate through 26 letters a-z, with deduplication applied after obtaining returned results\u003C\u002Fp>\u003Cp>Complete code can refer to the findallpeople function I added in ewsManage\u003C\u002Fp>\u003Ch4>(2) ResolveName operation\u003C\u002Fh4>\u003Cp>XML format example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:resolvenames returnfullcontactdata=\"false\" searchscope=\"ContactsActiveDirectory\">\u003Cbr>      \u003Cm:unresolvedentry>test\u003C\u002Fm:unresolvedentry>\u003Cbr>    \u003C\u002Fm:resolvenames>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Search string test, where the maximum number of query results returned is 100.\u003C\u002Fp>\u003Cp>To cover all results, the search criteria are combinations of any two letters, such as aa, ab, ac....zz, totaling 26*26=676 searches. Generally, this can cover all results, and deduplication is performed after obtaining the returned results.\u003C\u002Fp>\u003Cp>It is important to note that if the returned result for a search condition is 100, it indicates that the result for this condition may be incomplete (actual count greater than 100, only 100 obtained). Further subdivision is required, involving a third-level traversal. The returned results can be obtained by reading the TotalItemsInView item in the response content.\u003C\u002Fp>\u003Cp>For the complete code, refer to the resolveallname feature I added in ewsManage.\u003C\u002Fp>\u003Ch2>0x04 Methods to Disable GlobalAddressList\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>You can choose to specify whether a user is hidden in the Global Address List.\u003C\u002Fp>\u003Ch3>1. Via Exchange Admin Center (EAC)\u003C\u002Fh3>\u003Cp>Log in to the Exchange Control Panel (ECP) using an Exchange administrator account.\u003C\u002Fp>\u003Cp>Select the specified user, choose General, check Hide from address lists, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017507556_8_9de0bac2df-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Via Exchange Management Shell\u003C\u002Fh3>\u003Cp>Command to hide a specified user:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-MailContact -HiddenFromAddressListsEnabled $true -Identity test1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command to hide all users:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MailContact | Set-MailContact -HiddenFromAddressListsEnabled $true\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces common methods for obtaining the Exchange Global Address List under different conditions, describes writing programs to export the Global Address List via EWS's FindPeople operation and ResolveName operation respectively, and finally explains how to disable the Global Address List.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1262,"Onedaysec",6,"published","2026-02-02T07:51:00.264Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Exchange GlobalAddressList Penetration: Methods to Extract Email Addresses","Exchange GlobalAddressList, penetration testing, email extraction, OWA, EWS, MAPI over HTTP, Offline Address Book, security techniques",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],402,401,400,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.642Z","2026-07-23T16:01:30.302Z","draft","2026-07-23T16:05:55.284Z"]