What configuration options does Jason offer when trying to brute-force Exchange accounts?
Jason requires setting the Exchange server URL, the Exchange version (choosing a lower version for compatibility), the brute-force method (EWS, OAB, or Full), a username file, a password file, and the number of threads. It also allows adding a prefix or suffix to usernames via "Add to Username Start/End" fields. After a successful attack, it logs the valid credentials to a timestamped file.
configurationExchange versionEWSOABmultithreadusername dictionarypassword dictionary