[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fnt2SsAFg6Q1YZN28rBtRz8KHJ4mKRZ9XjQerbDpJW-s":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},344,"What configuration options does Jason offer when trying to brute-force Exchange accounts?","Jason requires setting the Exchange server URL, the Exchange version (choosing a lower version for compatibility), the brute-force method (EWS, OAB, or Full), a username file, a password file, and the number of threads. It also allows adding a prefix or suffix to usernames via \"Add to Username Start\u002FEnd\" fields. After a successful attack, it logs the valid credentials to a timestamped file.","\u003Cp>Jason requires setting the Exchange server URL, the Exchange version (choosing a lower version for compatibility), the brute-force method (EWS, OAB, or Full), a username file, a password file, and the number of threads. It also allows adding a prefix or suffix to usernames via &quot;Add to Username Start\u002FEnd&quot; fields. After a successful attack, it logs the valid credentials to a timestamped file.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fanalysis-of-apt34-leaked-tools-jason\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-configuration-options-does-jason-offer-when-trying-to-brute-force-exchange--1777484088232","configuration, Exchange version, EWS, OAB, multithread, username dictionary, password dictionary",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},87,"Analysis of APT34 Leaked Tools - Jason","analysis-of-apt34-leaked-tools-jason","Technical analysis of APT34's leaked Jason tool, fixing bugs for Exchange account brute-force attacks, with comparisons to open-source tools.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Jason is another tool leaked by Lab Dookhtegan on June 3, 2019, used for brute-force attacks on Exchange accounts\u003C\u002Fp>\u003Cp>However, although the leaked tool includes source code, it contains some bugs and cannot function properly\u003C\u002Fp>\u003Cp>This article will not analyze the connection between Jason and APT34, but will only focus on technical research: fixing Jason's bugs, restoring its functionality, analyzing the techniques used, and making horizontal comparisons with other open-source tools\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Previous analysis articles on APT34:\u003C\u002Fp>\u003Cp>\"Analysis of APT34 Leaked Tools - PoisonFrog and Glimpse\"\u003C\u002Fp>\u003Cp>\"Analysis of APT34 Leaked Tools - HighShell and HyperShell\"\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Open-source information about Jason\u003C\u002Fli>\u003Cli>Fixing Jason's bugs\u003C\u002Fli>\u003Cli>Actual testing of Jason\u003C\u002Fli>\u003Cli>Horizontal comparison with other open-source tools\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Open-source materials of Jason\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Jason was first leaked on a Telegram channel: https:\u002F\u002Ft.me\u002Flab_dookhtegana\u003C\u002Fp>\u003Cp>p3pperp0tts uploaded it to GitHub at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fp3pperp0tts\u002FAPT34\u002Ftree\u002Fmaster\u002FJason\u003C\u002Fp>\u003Cp>The decompiled_code folder contains the source code of Jason\u003C\u002Fp>\u003Cp>Jason uses EWS Managed API to access Exchange resources\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details on using EWS Managed API, refer to the previous article \"Exchange Web Service (EWS) Development Guide\"\u003C\u002Fp>\u003Cp>After simple fixes, I was able to compile it successfully in VS2015\u003C\u002Fp>\u003Cp>However, in the test environment, Jason failed to recognize the correct mailbox username and password, and all test results were unsuccessful\u003C\u002Fp>\u003Ch2>0x03 Fixing Jason's bug\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Compilation environment: VS2015\u003C\u002Fp>\u003Cp>To restore normal functionality, the source code needs to be modified at the following 4 locations\u003C\u002Fp>\u003Ch3>1. Add a reference to Microsoft.Exchange.WebServices.dll\u003C\u002Fh3>\u003Cp>Here, I placed Microsoft.Exchange.WebServices.dll in the same directory as the project and added a reference to it\u003C\u002Fp>\u003Ch3>2. Bug fix for certificate trust policy\u003C\u002Fh3>\u003Cp>Location: Form1.cs\u003C\u002Fp>\u003Cp>Original code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ServicePointManager.ServerCertificateValidationCallback = ((object \u003Cp0>, X509Certificate \u003Cp1>, X509Chain \u003Cp2>, SslPolicyErrors \u003Cp3>) =&gt; true);\u003C\u002Fp3>\u003C\u002Fp2>\u003C\u002Fp1>\u003C\u002Fp0>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modified code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ServicePointManager.ServerCertificateValidationCallback = (sender, certificate, chain, sslPolicyErrors) =&gt; { return true; };\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Bug fix for variable assignment\u003C\u002Fh3>\u003Cp>Location: Form1.cs\u003C\u002Fp>\u003Cp>(1) There are two locations in total\u003C\u002Fp>\u003Cp>Original code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.AppLocation + \"out.txt\";\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modified code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.AppLocation = MainConfig.AppLocation + \"out.txt\";\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) There are two locations\u003C\u002Fp>\u003Cp>Original code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.UsernameStart + userClass.Username + MainConfig.UsernameEnd;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modified code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>userClass.Username = MainConfig.UsernameStart + userClass.Username + MainConfig.UsernameEnd;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Issues with EWS and OAB judgment\u003C\u002Fh3>\u003Cp>After testing, the value of variable MainConfig.Method is always empty\u003C\u002Fp>\u003Cp>Need to fix the bug where MainConfig.Method cannot retrieve a value\u003C\u002Fp>\u003Cp>Location: Form1.cs\u003C\u002Fp>\u003Cp>Original code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.Method = this.cmbMethod.SelectedText;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modified code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.Method = (string)this.cmbMethod.SelectedItem;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>I have uploaded the complete functional project to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x04 Actual Test Jason\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After successful compilation, the file Jason.exe is generated\u003C\u002Fp>\u003Cp>The file Microsoft.Exchange.WebServices.dll is required in the same directory for the program to run properly\u003C\u002Fp>\u003Cp>After the program starts, the following configurations need to be set:\u003C\u002Fp>\u003Ch3>1. Exchange Address\u003C\u002Fh3>\u003Cp>Enter the URL of the Exchange server\u003C\u002Fp>\u003Cp>In my test environment, the Exchange Address is: https:\u002F\u002F192.168.206.17\u003C\u002Fp>\u003Ch3>2. Exchange Version\u003C\u002Fh3>\u003Cp>Select the corresponding version\u003C\u002Fp>\u003Cp>Choosing a lower version here can be compatible with higher versions of the Exchange server\u003C\u002Fp>\u003Ch3>3. BF Method\u003C\u002Fh3>\u003Cp>Three options:\u003C\u002Fp>\u003Cul>\u003Cli>EWS (Exchange Web Service)\u003C\u002Fli>\u003Cli>OAB (Offline Address Book)\u003C\u002Fli>\u003Cli>Full\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Typically select EWS\u003C\u002Fp>\u003Ch3>4. Username File\u003C\u002Fh3>\u003Cp>Username dictionary file\u003C\u002Fp>\u003Cp>Format can refer to the format indicated in PassSample.txt\u003C\u002Fp>\u003Cp>In my test environment, the format example I used is:\u003C\u002Fp>\u003Cp>test1@test.com\u003C\u002Fp>\u003Cp>admin@test.com\u003C\u002Fp>\u003Ch3>5. Password File\u003C\u002Fh3>\u003Cp>Password dictionary file\u003C\u002Fp>\u003Ch3>6. Number of Threads\u003C\u002Fh3>\u003Cp>Set the number of scanning threads\u003C\u002Fp>\u003Ch3>7. Generate Pass\u003C\u002Fh3>\u003Cp>Click to display the dictionary used for brute force attacks\u003C\u002Fp>\u003Ch3>8.Generate Pass Per\u003C\u002Fh3>\u003Cp>Click to generate a folder named PasswordPerUser, containing txt files named after each username with password dictionary content\u003C\u002Fp>\u003Ch3>9.Add to Username Start\u003C\u002Fh3>\u003Cp>Generate new users by adding input characters before the username\u003C\u002Fp>\u003Cp>Not recommended to set in test environments\u003C\u002Fp>\u003Ch3>10.Add to Username End\u003C\u002Fh3>\u003Cp>Generate new users by adding input characters after the username\u003C\u002Fp>\u003Cp>Not recommended to set in test environments\u003C\u002Fp>\u003Cp>In my test environment, the configuration is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018723006_0_745fc753e4.jpeg\">\u003C\u002Fp>\u003Cp>After successful brute force attack, generate log file out-year-month-day-hour-minute-second.txt, saving usernames and corresponding passwords\u003C\u002Fp>\u003Ch2>0x05 Horizontal comparison with other open-source tools\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1.Jason\u003C\u002Fh3>\u003Cul>\u003Cli>C# Implementation\u003C\u002Fli>\u003Cli>Brute force attack locations for Exchange:\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Fews\u002Fexchange.asmx\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Foab\u003C\u002Fli>\u003Cli>Supports multithreading\u003C\u002Fli>\u003Cli>GUI operation\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2.MailSniper\u003C\u002Fh3>\u003Cul>\u003Cli>https:\u002F\u002Fgithub.com\u002Fdafthack\u002FMailSniper\u003C\u002Fli>\u003Cli>PowerShell implementation\u003C\u002Fli>\u003Cli>Brute force attack locations for Exchange:\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Fews\u002Fexchange.asmx\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Fowa\u003C\u002Fli>\u003Cli>Supports multithreading\u003C\u002Fli>\u003Cli>Command-line operation\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>3.Ruler\u003C\u002Fh3>\u003Cul>\u003Cli>https:\u002F\u002Fgithub.com\u002Fsensepost\u002Fruler\u003C\u002Fli>\u003Cli>Go implementation\u003C\u002Fli>\u003Cli>Location for brute-forcing Exchange:\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Fautodiscover\u002Fautodiscover.xml\u003C\u002Fli>\u003Cli>Does not support multithreading\u003C\u002Fli>\u003Cli>Command-line operation\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For brute-forcing Exchange accounts, the principles are largely similar: all involve accessing Exchange web resources. A 401 response indicates authentication failure, while obtaining the expected result indicates correct user credentials.\u003C\u002Fp>\u003Cp>Compared to MailSniper and Ruler, Jason shares essentially the same principles and functionality. Personally, I believe this tool does not pose a risk of widespread abuse nor will it lead to advancements in malware techniques.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article describes how to fix Jason's bug, analyzes its underlying technology, provides a comparative analysis with other open-source tools, and concludes: personally, I believe this tool does not pose a risk of widespread abuse nor will it lead to advancements in malware techniques.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Jason is another tool leaked by Lab Dookhtegan on June 3, 2019, used for brute-force attacks on Exchange accounts\u003C\u002Fp>\u003Cp>However, although the leaked tool includes source code, it contains some bugs and cannot function properly\u003C\u002Fp>\u003Cp>This article will not analyze the connection between Jason and APT34, but will only focus on technical research: fixing Jason's bugs, restoring its functionality, analyzing the techniques used, and making horizontal comparisons with other open-source tools\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Previous analysis articles on APT34:\u003C\u002Fp>\u003Cp>\"Analysis of APT34 Leaked Tools - PoisonFrog and Glimpse\"\u003C\u002Fp>\u003Cp>\"Analysis of APT34 Leaked Tools - HighShell and HyperShell\"\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Open-source information about Jason\u003C\u002Fli>\u003Cli>Fixing Jason's bugs\u003C\u002Fli>\u003Cli>Actual testing of Jason\u003C\u002Fli>\u003Cli>Horizontal comparison with other open-source tools\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Open-source materials of Jason\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Jason was first leaked on a Telegram channel: https:\u002F\u002Ft.me\u002Flab_dookhtegana\u003C\u002Fp>\u003Cp>p3pperp0tts uploaded it to GitHub at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fp3pperp0tts\u002FAPT34\u002Ftree\u002Fmaster\u002FJason\u003C\u002Fp>\u003Cp>The decompiled_code folder contains the source code of Jason\u003C\u002Fp>\u003Cp>Jason uses EWS Managed API to access Exchange resources\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For details on using EWS Managed API, refer to the previous article \"Exchange Web Service (EWS) Development Guide\"\u003C\u002Fp>\u003Cp>After simple fixes, I was able to compile it successfully in VS2015\u003C\u002Fp>\u003Cp>However, in the test environment, Jason failed to recognize the correct mailbox username and password, and all test results were unsuccessful\u003C\u002Fp>\u003Ch2>0x03 Fixing Jason's bug\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Compilation environment: VS2015\u003C\u002Fp>\u003Cp>To restore normal functionality, the source code needs to be modified at the following 4 locations\u003C\u002Fp>\u003Ch3>1. Add a reference to Microsoft.Exchange.WebServices.dll\u003C\u002Fh3>\u003Cp>Here, I placed Microsoft.Exchange.WebServices.dll in the same directory as the project and added a reference to it\u003C\u002Fp>\u003Ch3>2. Bug fix for certificate trust policy\u003C\u002Fh3>\u003Cp>Location: Form1.cs\u003C\u002Fp>\u003Cp>Original code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ServicePointManager.ServerCertificateValidationCallback = ((object \u003Cp0>, X509Certificate \u003Cp1>, X509Chain \u003Cp2>, SslPolicyErrors \u003Cp3>) =&gt; true);\u003C\u002Fp3>\u003C\u002Fp2>\u003C\u002Fp1>\u003C\u002Fp0>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modified code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ServicePointManager.ServerCertificateValidationCallback = (sender, certificate, chain, sslPolicyErrors) =&gt; { return true; };\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Bug fix for variable assignment\u003C\u002Fh3>\u003Cp>Location: Form1.cs\u003C\u002Fp>\u003Cp>(1) There are two locations in total\u003C\u002Fp>\u003Cp>Original code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.AppLocation + \"out.txt\";\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modified code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.AppLocation = MainConfig.AppLocation + \"out.txt\";\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) There are two locations\u003C\u002Fp>\u003Cp>Original code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.UsernameStart + userClass.Username + MainConfig.UsernameEnd;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modified code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>userClass.Username = MainConfig.UsernameStart + userClass.Username + MainConfig.UsernameEnd;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Issues with EWS and OAB judgment\u003C\u002Fh3>\u003Cp>After testing, the value of variable MainConfig.Method is always empty\u003C\u002Fp>\u003Cp>Need to fix the bug where MainConfig.Method cannot retrieve a value\u003C\u002Fp>\u003Cp>Location: Form1.cs\u003C\u002Fp>\u003Cp>Original code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.Method = this.cmbMethod.SelectedText;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modified code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MainConfig.Method = (string)this.cmbMethod.SelectedItem;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>I have uploaded the complete functional project to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x04 Actual Test Jason\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After successful compilation, the file Jason.exe is generated\u003C\u002Fp>\u003Cp>The file Microsoft.Exchange.WebServices.dll is required in the same directory for the program to run properly\u003C\u002Fp>\u003Cp>After the program starts, the following configurations need to be set:\u003C\u002Fp>\u003Ch3>1. Exchange Address\u003C\u002Fh3>\u003Cp>Enter the URL of the Exchange server\u003C\u002Fp>\u003Cp>In my test environment, the Exchange Address is: https:\u002F\u002F192.168.206.17\u003C\u002Fp>\u003Ch3>2. Exchange Version\u003C\u002Fh3>\u003Cp>Select the corresponding version\u003C\u002Fp>\u003Cp>Choosing a lower version here can be compatible with higher versions of the Exchange server\u003C\u002Fp>\u003Ch3>3. BF Method\u003C\u002Fh3>\u003Cp>Three options:\u003C\u002Fp>\u003Cul>\u003Cli>EWS (Exchange Web Service)\u003C\u002Fli>\u003Cli>OAB (Offline Address Book)\u003C\u002Fli>\u003Cli>Full\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Typically select EWS\u003C\u002Fp>\u003Ch3>4. Username File\u003C\u002Fh3>\u003Cp>Username dictionary file\u003C\u002Fp>\u003Cp>Format can refer to the format indicated in PassSample.txt\u003C\u002Fp>\u003Cp>In my test environment, the format example I used is:\u003C\u002Fp>\u003Cp>test1@test.com\u003C\u002Fp>\u003Cp>admin@test.com\u003C\u002Fp>\u003Ch3>5. Password File\u003C\u002Fh3>\u003Cp>Password dictionary file\u003C\u002Fp>\u003Ch3>6. Number of Threads\u003C\u002Fh3>\u003Cp>Set the number of scanning threads\u003C\u002Fp>\u003Ch3>7. Generate Pass\u003C\u002Fh3>\u003Cp>Click to display the dictionary used for brute force attacks\u003C\u002Fp>\u003Ch3>8.Generate Pass Per\u003C\u002Fh3>\u003Cp>Click to generate a folder named PasswordPerUser, containing txt files named after each username with password dictionary content\u003C\u002Fp>\u003Ch3>9.Add to Username Start\u003C\u002Fh3>\u003Cp>Generate new users by adding input characters before the username\u003C\u002Fp>\u003Cp>Not recommended to set in test environments\u003C\u002Fp>\u003Ch3>10.Add to Username End\u003C\u002Fh3>\u003Cp>Generate new users by adding input characters after the username\u003C\u002Fp>\u003Cp>Not recommended to set in test environments\u003C\u002Fp>\u003Cp>In my test environment, the configuration is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018723006_0_745fc753e4-1.jpeg\">\u003C\u002Fp>\u003Cp>After successful brute force attack, generate log file out-year-month-day-hour-minute-second.txt, saving usernames and corresponding passwords\u003C\u002Fp>\u003Ch2>0x05 Horizontal comparison with other open-source tools\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1.Jason\u003C\u002Fh3>\u003Cul>\u003Cli>C# Implementation\u003C\u002Fli>\u003Cli>Brute force attack locations for Exchange:\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Fews\u002Fexchange.asmx\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Foab\u003C\u002Fli>\u003Cli>Supports multithreading\u003C\u002Fli>\u003Cli>GUI operation\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2.MailSniper\u003C\u002Fh3>\u003Cul>\u003Cli>https:\u002F\u002Fgithub.com\u002Fdafthack\u002FMailSniper\u003C\u002Fli>\u003Cli>PowerShell implementation\u003C\u002Fli>\u003Cli>Brute force attack locations for Exchange:\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Fews\u002Fexchange.asmx\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Fowa\u003C\u002Fli>\u003Cli>Supports multithreading\u003C\u002Fli>\u003Cli>Command-line operation\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>3.Ruler\u003C\u002Fh3>\u003Cul>\u003Cli>https:\u002F\u002Fgithub.com\u002Fsensepost\u002Fruler\u003C\u002Fli>\u003Cli>Go implementation\u003C\u002Fli>\u003Cli>Location for brute-forcing Exchange:\u003C\u002Fli>\u003Cli>https:\u002F\u002Furl\u002Fautodiscover\u002Fautodiscover.xml\u003C\u002Fli>\u003Cli>Does not support multithreading\u003C\u002Fli>\u003Cli>Command-line operation\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For brute-forcing Exchange accounts, the principles are largely similar: all involve accessing Exchange web resources. A 401 response indicates authentication failure, while obtaining the expected result indicates correct user credentials.\u003C\u002Fp>\u003Cp>Compared to MailSniper and Ruler, Jason shares essentially the same principles and functionality. Personally, I believe this tool does not pose a risk of widespread abuse nor will it lead to advancements in malware techniques.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article describes how to fix Jason's bug, analyzes its underlying technology, provides a comparative analysis with other open-source tools, and concludes: personally, I believe this tool does not pose a risk of widespread abuse nor will it lead to advancements in malware techniques.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1357,"Onedaysec",4,"published","2026-02-02T08:06:13.162Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Fix APT34 Jason Tool Bugs & Exchange Brute-Force Analysis","APT34, Jason tool, Exchange brute-force, EWS API, bug fixes, cybersecurity analysis",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46,47],345,343,342,341,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.040Z","2026-07-23T16:01:24.781Z","draft","2026-07-23T16:05:30.012Z"]