[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fdtHWHQTpTe63UjCFpNuFXoIFvsbLYzVtdJ_mRY-HuMg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},157,"What is the Autodiscover service in Exchange and how can it be used in penetration testing?","Autodiscover is an Exchange service that automatically configures client applications like Outlook by requiring only an email address and password. During penetration testing, once you have email user credentials, you can use Autodiscover to brute-force passwords (via NTLM authentication), read configuration information (including the domain controller's computer name), and access Exchange mail resources like the Global Address List. This makes it a valuable tool for lateral movement and information gathering. For more details, see the original article [Penetration Basics - Using Exchange Autodiscover](\u002Fnews\u002Fpenetration-basics-using-exchange-autodiscover).","\u003Cp>Autodiscover is an Exchange service that automatically configures client applications like Outlook by requiring only an email address and password. During penetration testing, once you have email user credentials, you can use Autodiscover to brute-force passwords (via NTLM authentication), read configuration information (including the domain controller&#39;s computer name), and access Exchange mail resources like the Global Address List. This makes it a valuable tool for lateral movement and information gathering. For more details, see the original article [Penetration Basics - Using Exchange Autodiscover](\u002Fnews\u002Fpenetration-basics-using-exchange-autodiscover).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-using-exchange-autodiscover\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-autodiscover-service-in-exchange-and-how-can-it-be-used-in-penetrati-1777484983584","Autodiscover, Exchange, NTLM authentication, password brute-forcing, penetration testing",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},42,"Penetration Basics - Using Exchange Autodiscover","penetration-basics-using-exchange-autodiscover","Learn to exploit Exchange Autodiscover for password brute-forcing, reading config info, and accessing email resources in penetration testing scenarios.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Autodiscover is a service in Exchange designed to simplify the configuration process for client applications. Users only need to enter their email address and password to obtain the necessary configuration information for running client applications through the Autodiscover service.\u003C\u002Fp>\u003Cp>In penetration testing, when we obtain the credentials of an email user, we can use the Autodiscover service to uncover more valuable information.\u003C\u002Fp>\u003Cp>This article will introduce methods for reading configuration information through the Autodiscover service, provide open-source implementation code, and share exploitation ideas.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Methods for password brute-forcing via Autodiscover\u003C\u002Fli>\u003Cli>Methods for reading configuration information via Autodiscover\u003C\u002Fli>\u003Cli>Methods for accessing Exchange email resources via Autodiscover\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods for Password Brute-Forcing via Autodiscover\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Corresponding URL: https:\u002F\u002F\u003Cdomain>\u002Fautodiscover\u002Fautodiscover.xml\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>Authentication method: NTLM Over HTTP Protocol (supports both plaintext and NTLM hash login)\u003C\u002Fp>\u003Cp>Login failure returns 401\u003C\u002Fp>\u003Cp>Login success returns 200, content example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Cautodiscover xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fautodiscover\u002Fresponseschema\u002F2006\">\u003Cbr>  \u003Cresponse>\u003Cbr>    \u003Cerror time=\"01:37:11.6638388\" id=\"2403276782\">\u003Cbr>      \u003Cerrorcode>600\u003C\u002Ferrorcode>\u003Cbr>      \u003Cmessage>Invalid Request\u003C\u002Fmessage>\u003Cbr>      \u003Cdebugdata>\u003Cbr>    \u003C\u002Fdebugdata>\u003C\u002Ferror>\u003Cbr>  \u003C\u002Fresponse>\u003Cbr>\u003C\u002Fautodiscover>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>We can see that the authentication process for Autodiscover is basically the same as EWS, so the code implementation can also refer to the previous code checkEWS.py\u003C\u002Fp>\u003Cp>No further introduction here, specific details can refer to the previous article \"Penetration Techniques - Pass the Hash with Exchange Web Service\"\u003C\u002Fp>\u003Cp>Refer to the checkautodiscover function in checkAutodiscover.py for implementation code.\u003C\u002Fp>\u003Ch2>0x03 Method for reading configuration information via Autodiscover\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Directly access https:\u002F\u002F\u003Cdomain>\u002Fautodiscover\u002Fautodiscover.xml via a browser\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>Unable to obtain configuration information; example content returned by the browser:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Cautodiscover xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fautodiscover\u002Fresponseschema\u002F2006\">\u003Cbr>  \u003Cresponse>\u003Cbr>    \u003Cerror time=\"01:37:11.6638388\" id=\"2403276782\">\u003Cbr>      \u003Cerrorcode>600\u003C\u002Ferrorcode>\u003Cbr>      \u003Cmessage>Invalid Request\u003C\u002Fmessage>\u003Cbr>      \u003Cdebugdata>\u003Cbr>    \u003C\u002Fdebugdata>\u003C\u002Ferror>\u003Cbr>  \u003C\u002Fresponse>\u003Cbr>\u003C\u002Fautodiscover>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019787138_0_3d7f9ac162.jpeg\">\u003C\u002Fp>\u003Cp>To read configuration information, we need to perform the following operations:\u003C\u002Fp>\u003Cp>1. Send a GET request, add NTLM authentication information in the Header, example: Authorization: NTLM xxxxxxxxxxx\u003C\u002Fp>\u003Cp>URL is \u002Fautodiscover\u002Fautodiscover.xml\u003C\u002Fp>\u003Cp>Specify the encoding format as gzip, format as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Accept-Encoding: gzip\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Receive the returned result\u003C\u002Fp>\u003Cp>Prompt 401 Unauthorized\u003C\u002Fp>\u003Cp>3. Send a POST request\u003C\u002Fp>\u003Cp>Complete NTLM authentication in the Header, and additionally add the following information (X-Anchormailbox) in the Header, specifying the current user's email address, example: X-Anchormailbox: test1@test.com\u003C\u002Fp>\u003Cp>The content format of the POST request is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cautodiscover xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fautodiscover\u002Foutlook\u002Frequestschema\u002F2006\">\u003Cbr>\u003Crequest>\u003Cemailaddress>{EMailAddress}\u003C\u002Femailaddress>\u003Cbr>\u003Cacceptableresponseschema>http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fautodiscover\u002Foutlook\u002Fresponseschema\u002F2006a\u003C\u002Facceptableresponseschema>\u003Cbr>\u003C\u002Frequest>\u003C\u002Fautodiscover>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>where {EMailAddress} is the current user's email address\u003C\u002Fp>\u003Cp>Complete packet example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>POST \u002Fautodiscover\u002Fautodiscover.xml HTTP\u002F1.1\u003Cbr>Host: 192.168.1.1\u003Cbr>Content-Length: 351\u003Cbr>Authorization: NTLM TlRMTVNTUAADAAAAGAAYAHYAAACuAK4AjgAAABYAFgBAAAAACgAKAFYAAAAWABYAYAAAAAAAAAA8AQAABQKIoDEAOQAyAC4AMQA4ADgALgAxAC4AMQB0AGUAcwB0ADEAMQA5ADIALgAxADYAOAAuADEALgAxABlZOdtFpFcfJQY7ysotO0RJVlczdGVrae1Bq6PIhSQWZ5F4VJTTyL8BAQAAAAAAAOiYz4Q0XtYBSVZXM3Rla2kAAAAAAgAIAFQARQBTAFQAAQAGAEQAQwAxAAQAEABAAGUAcwB0AC4AYwBvAG0AAwAYAGQAYwAxAC4AdABlAHMAdAAuAGMAbwBtAAUAEAB0AGUAcwB0AC4AYwBvAG0ABwAIAOiYz3Q0XtYBCQAQAGMAaQBmAHMALwBEAEMAMQAAAAAAAAAAAA==\u003Cbr>Content-type: text\u002Fxml\u003Cbr>X-Anchormailbox: test1@test.com\u003Cbr>X-Mapihttpcapability: 1\u003Cbr>Accept-Encoding: gzip\u003Cbr>\u003Cbr>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cautodiscover xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fautodiscover\u002Foutlook\u002Frequestschema\u002F2006\">\u003Cbr>\u003Crequest>\u003Cemailaddress>test1@test.com\u003C\u002Femailaddress>\u003Cbr>\u003Cacceptableresponseschema>http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fautodiscover\u002Foutlook\u002Fresponseschema\u002F2006a\u003C\u002Facceptableresponseschema>\u003Cbr>\u003C\u002Frequest>\u003C\u002Fautodiscover>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>4. Receive the returned result\u003C\u002Fp>\u003Cp>Indicates 200 OK\u003C\u002Fp>\u003Cp>The returned Body content is in gzip compressed format and needs to be decoded\u003C\u002Fp>\u003Cp>The content obtained varies across different versions of Exchange, with some common elements as follows:\u003C\u002Fp>\u003Cul>\u003Cli>DisplayName\u003C\u002Fli>\u003Cli>LegacyDN\u003C\u002Fli>\u003Cli>AutoDiscoverSMTPAddress\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Notably, AD represents the computer name of the domain controller. Information about AD can be obtained in Exchange 2013 and older versions, but not in Exchange 2016\u003C\u002Fp>\u003Cp>The implementation code for the above can be referenced in the checkautodiscover function in checkAutodiscover.py\u003C\u002Fp>\u003Cp>A previous article, 'Penetration Techniques—Accessing Internal File Shares via Exchange ActiveSync', introduced a method to access the domain shared directory SYSVOL via Exchange ActiveSync. The path here needs to specify the computer name of the domain controller\u003C\u002Fp>\u003Cp>Correct format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\\\\dc1\\SYSVOL\\test.com\\Policies\\{6AC1786C-016F-11D2-945F-00C04fB984F9}\\GPT.INI\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Incorrect format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\\\\test.com\\SYSVOL\\test.com\\Policies\\{6AC1786C-016F-11D2-945F-00C04fB984F9}\\GPT.INI\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By combining the above two points, the complete implementation of reading files from the domain shared directory SYSVOL can be achieved\u003C\u002Fp>\u003Cp>To support Exchange 2016, a more universal method (supporting all versions) for obtaining the domain controller computer name is introduced here: by reading the current user's configuration information through EWS, thereby obtaining the domain controller's computer name.\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fexchange-web-services\u002Fhow-to-get-user-settings-from-exchange-by-using-autodiscover\u003C\u002Fp>\u003Cp>Note that the request URL should be \u002Fautodiscover\u002Fautodiscover.svc, not \u002FEWS\u002FExchange.asmx.\u003C\u002Fp>\u003Cp>Example of the SOAP format to send:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:a=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002F2010\u002FAutodiscover\" xmlns:wsa=\"http:\u002F\u002Fwww.w3.org\u002F2005\u002F08\u002Faddressing\" xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ca:requestedserverversion>Exchange2013_SP1\u003C\u002Fa:requestedserverversion>\u003Cbr>    \u003Cwsa:action>http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002F2010\u002FAutodiscover\u002FAutodiscover\u002FGetUserSettings\u003C\u002Fwsa:action>\u003Cbr>    \u003Cwsa:to>https:\u002F\u002F{domain}\u002Fautodiscover\u002Fautodiscover.svc\u003C\u002Fwsa:to>\u003Cbr>  \u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Ca:getusersettingsrequestmessage xmlns:a=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002F2010\u002FAutodiscover\">\u003Cbr>      \u003Ca:request>\u003Cbr>        \u003Ca:users>\u003Cbr>          \u003Ca:user>\u003Cbr>            \u003Ca:mailbox>{mail}\u003C\u002Fa:mailbox>\u003Cbr>          \u003C\u002Fa:user>\u003Cbr>        \u003C\u002Fa:users>\u003Cbr>        \u003Ca:requestedsettings>\u003Cbr>          \u003Ca:setting>UserDisplayName\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>UserDN\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>UserDeploymentId\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>InternalMailboxServer\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>MailboxDN\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>PublicFolderServer\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>ActiveDirectoryServer\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>ExternalMailboxServer\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>EcpDeliveryReportUrlFragment\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>EcpPublishingUrlFragment\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>EcpTextMessagingUrlFragment\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>ExternalEwsUrl\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>CasVersion\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>EwsSupportedSchemas\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>GroupingInformation\u003C\u002Fa:setting>\u003Cbr>        \u003C\u002Fa:requestedsettings>\u003Cbr>      \u003C\u002Fa:request>\u003Cbr>    \u003C\u002Fa:getusersettingsrequestmessage>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Note that {domain} must be a domain name, not an IP address\u003C\u002Fp>\u003Cp>In the returned results, ActiveDirectoryServer represents the computer name of the domain controller, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019797661_1_d751e20f03.jpeg\">\u003C\u002Fp>\u003Cp>Implementation code can refer to the getusersetting function in checkAutodiscover.py\u003C\u002Fp>\u003Ch2>0x04 Method to Access Exchange Mail Resources via Autodiscover\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After completing authentication via Autodiscover, MAPI OVER HTTP can be used to access Exchange mail resources\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>MAPI OVER HTTP is the default communication protocol between Outlook and Exchange 2016\u003C\u002Fp>\u003Cp>MAPI OVER HTTP is a new transport protocol implemented in Exchange Server 2013 Service Pack 1 (SP1), replacing RPC OVER HTTP (also known as Outlook Anywhere)\u003C\u002Fp>\u003Cp>MAPI OVER HTTP is not enabled by default in Exchange 2013; the communication protocol between Outlook and Exchange uses RPC OVER HTTP\u003C\u002Fp>\u003Cp>For reference on MAPI OVER HTTP:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fopenspecs\u002Fexchange_server_protocols\u002Fms-oxcmapihttp\u002Fd502edcf-0b22-42f2-8500-019f00d60245\u003C\u002Fp>\u003Cp>https:\u002F\u002Finteroperability.blob.core.windows.net\u002Ffiles\u002FMS-OXCMAPIHTTP\u002F%5BMS-OXCMAPIHTTP%5D.pdf\u003C\u002Fp>\u003Cp>ruler also supports some functions of MAPI OVER HTTP and can be used as a reference\u003C\u002Fp>\u003Ch3>1. Execute command\u003C\u002Fh3>\u003Cp>Process:\u003C\u002Fp>\u003Col>\u003Cli>connect\u003C\u002Fli>\u003Cli>execute\u003C\u002Fli>\u003Cli>disconnect\u003C\u002Fli>\u003C\u002Fol>\u003Ch3>2. Read GlobalAddressList via Offline Address Book (OAB)\u003C\u002Fh3>\u003Cp>Using checkAutodiscover.py\u003C\u002Fp>\u003Ch4>(1) Obtain OABUrl through Autodiscover\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python checkAutodiscover.py 192.168.1.1 443 plaintext test1@test.com DomainUser123! checkautodiscover\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019810027_2_fcfe5121f8.jpeg\">\u003C\u002Fp>\u003Cp>Obtained OABUrl is https:\u002F\u002Fdc1.test.com\u002FOAB\u002F9e3fa457-ebf1-40e4-b265-21d09a62872b\u002F\u003C\u002Fp>\u003Ch4>(2) Access OABUrl to find the lzx file name corresponding to Default Global Address\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python checkAutodiscover.py 192.168.1.1 443 plaintext test1@test.com DomainUser123! checkoab\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019822297_3_d5591fe5a6.jpeg\">\u003C\u002Fp>\u003Cp>Obtained Default Global Address is 4667c322-5c08-4cda-844a-253ff36b4a6a-data-5.lzx\u003C\u002Fp>\u003Ch4>(3) Download lxz file\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python checkAutodiscover.py 192.168.1.1 443 plaintext test1@test.com DomainUser123! downloadlzx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019832447_4_e2e2e2a152.jpeg\">\u003C\u002Fp>\u003Ch4>(4) Decode the lxz file\u003C\u002Fh4>\u003Cp>Using the tool oabextract\u003C\u002Fp>\u003Cp>Installation required after download\u003C\u002Fp>\u003Cp>Download link for a pre-compiled version ready to use directly on Kali: http:\u002F\u002Fx2100.icecube.wisc.edu\u002Fdownloads\u002Fpython\u002Fpython2.6.Linux-x86_64.gcc-4.4.4\u002Fbin\u002Foabextract\u003C\u002Fp>\u003Cp>Command example to convert lzx file to oab file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>oabextract 4667c322-5c08-4cda-844a-253ff36b4a6a-data-5.lzx gal.oab\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command example to extract GAL:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>strings gal.oab|grep SMTP\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019849550_5_f91d66a6cc.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods for password brute-forcing via Autodiscover, reading configuration information, and accessing Exchange email resources, along with open-source implementation code and exploitation ideas.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Autodiscover is a service in Exchange designed to simplify the configuration process for client applications. Users only need to enter their email address and password to obtain the necessary configuration information for running client applications through the Autodiscover service.\u003C\u002Fp>\u003Cp>In penetration testing, when we obtain the credentials of an email user, we can use the Autodiscover service to uncover more valuable information.\u003C\u002Fp>\u003Cp>This article will introduce methods for reading configuration information through the Autodiscover service, provide open-source implementation code, and share exploitation ideas.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Methods for password brute-forcing via Autodiscover\u003C\u002Fli>\u003Cli>Methods for reading configuration information via Autodiscover\u003C\u002Fli>\u003Cli>Methods for accessing Exchange email resources via Autodiscover\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods for Password Brute-Forcing via Autodiscover\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Corresponding URL: https:\u002F\u002F\u003Cdomain>\u002Fautodiscover\u002Fautodiscover.xml\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>Authentication method: NTLM Over HTTP Protocol (supports both plaintext and NTLM hash login)\u003C\u002Fp>\u003Cp>Login failure returns 401\u003C\u002Fp>\u003Cp>Login success returns 200, content example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Cautodiscover xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fautodiscover\u002Fresponseschema\u002F2006\">\u003Cbr>  \u003Cresponse>\u003Cbr>    \u003Cerror time=\"01:37:11.6638388\" id=\"2403276782\">\u003Cbr>      \u003Cerrorcode>600\u003C\u002Ferrorcode>\u003Cbr>      \u003Cmessage>Invalid Request\u003C\u002Fmessage>\u003Cbr>      \u003Cdebugdata>\u003Cbr>    \u003C\u002Fdebugdata>\u003C\u002Ferror>\u003Cbr>  \u003C\u002Fresponse>\u003Cbr>\u003C\u002Fautodiscover>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>We can see that the authentication process for Autodiscover is basically the same as EWS, so the code implementation can also refer to the previous code checkEWS.py\u003C\u002Fp>\u003Cp>No further introduction here, specific details can refer to the previous article \"Penetration Techniques - Pass the Hash with Exchange Web Service\"\u003C\u002Fp>\u003Cp>Refer to the checkautodiscover function in checkAutodiscover.py for implementation code.\u003C\u002Fp>\u003Ch2>0x03 Method for reading configuration information via Autodiscover\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Directly access https:\u002F\u002F\u003Cdomain>\u002Fautodiscover\u002Fautodiscover.xml via a browser\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>Unable to obtain configuration information; example content returned by the browser:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Cautodiscover xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fautodiscover\u002Fresponseschema\u002F2006\">\u003Cbr>  \u003Cresponse>\u003Cbr>    \u003Cerror time=\"01:37:11.6638388\" id=\"2403276782\">\u003Cbr>      \u003Cerrorcode>600\u003C\u002Ferrorcode>\u003Cbr>      \u003Cmessage>Invalid Request\u003C\u002Fmessage>\u003Cbr>      \u003Cdebugdata>\u003Cbr>    \u003C\u002Fdebugdata>\u003C\u002Ferror>\u003Cbr>  \u003C\u002Fresponse>\u003Cbr>\u003C\u002Fautodiscover>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019787138_0_3d7f9ac162-1.jpeg\">\u003C\u002Fp>\u003Cp>To read configuration information, we need to perform the following operations:\u003C\u002Fp>\u003Cp>1. Send a GET request, add NTLM authentication information in the Header, example: Authorization: NTLM xxxxxxxxxxx\u003C\u002Fp>\u003Cp>URL is \u002Fautodiscover\u002Fautodiscover.xml\u003C\u002Fp>\u003Cp>Specify the encoding format as gzip, format as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Accept-Encoding: gzip\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Receive the returned result\u003C\u002Fp>\u003Cp>Prompt 401 Unauthorized\u003C\u002Fp>\u003Cp>3. Send a POST request\u003C\u002Fp>\u003Cp>Complete NTLM authentication in the Header, and additionally add the following information (X-Anchormailbox) in the Header, specifying the current user's email address, example: X-Anchormailbox: test1@test.com\u003C\u002Fp>\u003Cp>The content format of the POST request is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cautodiscover xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fautodiscover\u002Foutlook\u002Frequestschema\u002F2006\">\u003Cbr>\u003Crequest>\u003Cemailaddress>{EMailAddress}\u003C\u002Femailaddress>\u003Cbr>\u003Cacceptableresponseschema>http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fautodiscover\u002Foutlook\u002Fresponseschema\u002F2006a\u003C\u002Facceptableresponseschema>\u003Cbr>\u003C\u002Frequest>\u003C\u002Fautodiscover>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>where {EMailAddress} is the current user's email address\u003C\u002Fp>\u003Cp>Complete packet example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>POST \u002Fautodiscover\u002Fautodiscover.xml HTTP\u002F1.1\u003Cbr>Host: 192.168.1.1\u003Cbr>Content-Length: 351\u003Cbr>Authorization: NTLM TlRMTVNTUAADAAAAGAAYAHYAAACuAK4AjgAAABYAFgBAAAAACgAKAFYAAAAWABYAYAAAAAAAAAA8AQAABQKIoDEAOQAyAC4AMQA4ADgALgAxAC4AMQB0AGUAcwB0ADEAMQA5ADIALgAxADYAOAAuADEALgAxABlZOdtFpFcfJQY7ysotO0RJVlczdGVrae1Bq6PIhSQWZ5F4VJTTyL8BAQAAAAAAAOiYz4Q0XtYBSVZXM3Rla2kAAAAAAgAIAFQARQBTAFQAAQAGAEQAQwAxAAQAEABAAGUAcwB0AC4AYwBvAG0AAwAYAGQAYwAxAC4AdABlAHMAdAAuAGMAbwBtAAUAEAB0AGUAcwB0AC4AYwBvAG0ABwAIAOiYz3Q0XtYBCQAQAGMAaQBmAHMALwBEAEMAMQAAAAAAAAAAAA==\u003Cbr>Content-type: text\u002Fxml\u003Cbr>X-Anchormailbox: test1@test.com\u003Cbr>X-Mapihttpcapability: 1\u003Cbr>Accept-Encoding: gzip\u003Cbr>\u003Cbr>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cautodiscover xmlns=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fautodiscover\u002Foutlook\u002Frequestschema\u002F2006\">\u003Cbr>\u003Crequest>\u003Cemailaddress>test1@test.com\u003C\u002Femailaddress>\u003Cbr>\u003Cacceptableresponseschema>http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002Fautodiscover\u002Foutlook\u002Fresponseschema\u002F2006a\u003C\u002Facceptableresponseschema>\u003Cbr>\u003C\u002Frequest>\u003C\u002Fautodiscover>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>4. Receive the returned result\u003C\u002Fp>\u003Cp>Indicates 200 OK\u003C\u002Fp>\u003Cp>The returned Body content is in gzip compressed format and needs to be decoded\u003C\u002Fp>\u003Cp>The content obtained varies across different versions of Exchange, with some common elements as follows:\u003C\u002Fp>\u003Cul>\u003Cli>DisplayName\u003C\u002Fli>\u003Cli>LegacyDN\u003C\u002Fli>\u003Cli>AutoDiscoverSMTPAddress\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Notably, AD represents the computer name of the domain controller. Information about AD can be obtained in Exchange 2013 and older versions, but not in Exchange 2016\u003C\u002Fp>\u003Cp>The implementation code for the above can be referenced in the checkautodiscover function in checkAutodiscover.py\u003C\u002Fp>\u003Cp>A previous article, 'Penetration Techniques—Accessing Internal File Shares via Exchange ActiveSync', introduced a method to access the domain shared directory SYSVOL via Exchange ActiveSync. The path here needs to specify the computer name of the domain controller\u003C\u002Fp>\u003Cp>Correct format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\\\\dc1\\SYSVOL\\test.com\\Policies\\{6AC1786C-016F-11D2-945F-00C04fB984F9}\\GPT.INI\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Incorrect format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\\\\test.com\\SYSVOL\\test.com\\Policies\\{6AC1786C-016F-11D2-945F-00C04fB984F9}\\GPT.INI\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By combining the above two points, the complete implementation of reading files from the domain shared directory SYSVOL can be achieved\u003C\u002Fp>\u003Cp>To support Exchange 2016, a more universal method (supporting all versions) for obtaining the domain controller computer name is introduced here: by reading the current user's configuration information through EWS, thereby obtaining the domain controller's computer name.\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fexchange\u002Fclient-developer\u002Fexchange-web-services\u002Fhow-to-get-user-settings-from-exchange-by-using-autodiscover\u003C\u002Fp>\u003Cp>Note that the request URL should be \u002Fautodiscover\u002Fautodiscover.svc, not \u002FEWS\u002FExchange.asmx.\u003C\u002Fp>\u003Cp>Example of the SOAP format to send:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\"?-->\u003Cbr>\u003Csoap:envelope xmlns:a=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002F2010\u002FAutodiscover\" xmlns:wsa=\"http:\u002F\u002Fwww.w3.org\u002F2005\u002F08\u002Faddressing\" xmlns:xsi=\"http:\u002F\u002Fwww.w3.org\u002F2001\u002FXMLSchema-instance\" xmlns:soap=\"http:\u002F\u002Fschemas.xmlsoap.org\u002Fsoap\u002Fenvelope\u002F\">\u003Cbr>  \u003Csoap:header>\u003Cbr>    \u003Ca:requestedserverversion>Exchange2013_SP1\u003C\u002Fa:requestedserverversion>\u003Cbr>    \u003Cwsa:action>http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002F2010\u002FAutodiscover\u002FAutodiscover\u002FGetUserSettings\u003C\u002Fwsa:action>\u003Cbr>    \u003Cwsa:to>https:\u002F\u002F{domain}\u002Fautodiscover\u002Fautodiscover.svc\u003C\u002Fwsa:to>\u003Cbr>  \u003C\u002Fsoap:header>\u003Cbr>  \u003Csoap:body>\u003Cbr>    \u003Ca:getusersettingsrequestmessage xmlns:a=\"http:\u002F\u002Fschemas.microsoft.com\u002Fexchange\u002F2010\u002FAutodiscover\">\u003Cbr>      \u003Ca:request>\u003Cbr>        \u003Ca:users>\u003Cbr>          \u003Ca:user>\u003Cbr>            \u003Ca:mailbox>{mail}\u003C\u002Fa:mailbox>\u003Cbr>          \u003C\u002Fa:user>\u003Cbr>        \u003C\u002Fa:users>\u003Cbr>        \u003Ca:requestedsettings>\u003Cbr>          \u003Ca:setting>UserDisplayName\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>UserDN\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>UserDeploymentId\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>InternalMailboxServer\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>MailboxDN\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>PublicFolderServer\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>ActiveDirectoryServer\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>ExternalMailboxServer\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>EcpDeliveryReportUrlFragment\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>EcpPublishingUrlFragment\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>EcpTextMessagingUrlFragment\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>ExternalEwsUrl\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>CasVersion\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>EwsSupportedSchemas\u003C\u002Fa:setting>\u003Cbr>          \u003Ca:setting>GroupingInformation\u003C\u002Fa:setting>\u003Cbr>        \u003C\u002Fa:requestedsettings>\u003Cbr>      \u003C\u002Fa:request>\u003Cbr>    \u003C\u002Fa:getusersettingsrequestmessage>\u003Cbr>  \u003C\u002Fsoap:body>\u003Cbr>\u003C\u002Fsoap:envelope>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Note that {domain} must be a domain name, not an IP address\u003C\u002Fp>\u003Cp>In the returned results, ActiveDirectoryServer represents the computer name of the domain controller, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019797661_1_d751e20f03-1.jpeg\">\u003C\u002Fp>\u003Cp>Implementation code can refer to the getusersetting function in checkAutodiscover.py\u003C\u002Fp>\u003Ch2>0x04 Method to Access Exchange Mail Resources via Autodiscover\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After completing authentication via Autodiscover, MAPI OVER HTTP can be used to access Exchange mail resources\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>MAPI OVER HTTP is the default communication protocol between Outlook and Exchange 2016\u003C\u002Fp>\u003Cp>MAPI OVER HTTP is a new transport protocol implemented in Exchange Server 2013 Service Pack 1 (SP1), replacing RPC OVER HTTP (also known as Outlook Anywhere)\u003C\u002Fp>\u003Cp>MAPI OVER HTTP is not enabled by default in Exchange 2013; the communication protocol between Outlook and Exchange uses RPC OVER HTTP\u003C\u002Fp>\u003Cp>For reference on MAPI OVER HTTP:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fopenspecs\u002Fexchange_server_protocols\u002Fms-oxcmapihttp\u002Fd502edcf-0b22-42f2-8500-019f00d60245\u003C\u002Fp>\u003Cp>https:\u002F\u002Finteroperability.blob.core.windows.net\u002Ffiles\u002FMS-OXCMAPIHTTP\u002F%5BMS-OXCMAPIHTTP%5D.pdf\u003C\u002Fp>\u003Cp>ruler also supports some functions of MAPI OVER HTTP and can be used as a reference\u003C\u002Fp>\u003Ch3>1. Execute command\u003C\u002Fh3>\u003Cp>Process:\u003C\u002Fp>\u003Col>\u003Cli>connect\u003C\u002Fli>\u003Cli>execute\u003C\u002Fli>\u003Cli>disconnect\u003C\u002Fli>\u003C\u002Fol>\u003Ch3>2. Read GlobalAddressList via Offline Address Book (OAB)\u003C\u002Fh3>\u003Cp>Using checkAutodiscover.py\u003C\u002Fp>\u003Ch4>(1) Obtain OABUrl through Autodiscover\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python checkAutodiscover.py 192.168.1.1 443 plaintext test1@test.com DomainUser123! checkautodiscover\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019810027_2_fcfe5121f8-1.jpeg\">\u003C\u002Fp>\u003Cp>Obtained OABUrl is https:\u002F\u002Fdc1.test.com\u002FOAB\u002F9e3fa457-ebf1-40e4-b265-21d09a62872b\u002F\u003C\u002Fp>\u003Ch4>(2) Access OABUrl to find the lzx file name corresponding to Default Global Address\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python checkAutodiscover.py 192.168.1.1 443 plaintext test1@test.com DomainUser123! checkoab\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019822297_3_d5591fe5a6-1.jpeg\">\u003C\u002Fp>\u003Cp>Obtained Default Global Address is 4667c322-5c08-4cda-844a-253ff36b4a6a-data-5.lzx\u003C\u002Fp>\u003Ch4>(3) Download lxz file\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python checkAutodiscover.py 192.168.1.1 443 plaintext test1@test.com DomainUser123! downloadlzx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019832447_4_e2e2e2a152-1.jpeg\">\u003C\u002Fp>\u003Ch4>(4) Decode the lxz file\u003C\u002Fh4>\u003Cp>Using the tool oabextract\u003C\u002Fp>\u003Cp>Installation required after download\u003C\u002Fp>\u003Cp>Download link for a pre-compiled version ready to use directly on Kali: http:\u002F\u002Fx2100.icecube.wisc.edu\u002Fdownloads\u002Fpython\u002Fpython2.6.Linux-x86_64.gcc-4.4.4\u002Fbin\u002Foabextract\u003C\u002Fp>\u003Cp>Command example to convert lzx file to oab file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>oabextract 4667c322-5c08-4cda-844a-253ff36b4a6a-data-5.lzx gal.oab\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command example to extract GAL:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>strings gal.oab|grep SMTP\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019849550_5_f91d66a6cc-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods for password brute-forcing via Autodiscover, reading configuration information, and accessing Exchange email resources, along with open-source implementation code and exploitation ideas.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1596,"Onedaysec",5,"published","2026-02-02T08:19:47.663Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Exchange Autodiscover Penetration Testing: Brute Force & Info Leak","Exchange Autodiscover, penetration testing, password brute force, configuration leak, NTLM authentication, email security, Exchange exploit, Autodiscover.xml, EWS, hash pass",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,47,4],161,160,159,158,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.018Z","2026-07-23T16:01:05.684Z","draft","2026-07-23T16:04:05.307Z"]