Get a Pentest and security assessment of your IT network.

News

Abusing Exchange: One API call away from Domain Admin

In most organisations using Active Directory and Exchange servers, Exchange servers have such high privileges that being Administrator on an Exchange server is enough to escalate to Domain Admin. This attack is possible by default and while no patches are available at the point of writing, there are mitigations that can be applied to prevent this privilege escalation. There are 3 components which are combined to escalate from any user with a mailbox to domain Admin access: Exchange Servers have (too) high privileges by default. NTLM authentication is vulnerable to relay attacks instead of a reflection attack, we can grant ourselves DCSync rights.”]

Source: https://dirkjanm.io/abusing-exchange-one-api-call-away-from-domain-admin/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin