#owassrf — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #owassrf, aggregated by home.social.
-
Wie die #HAW #Hamburg geransomwared wurde? Vielleicht so:
haw-mailer.haw-hamburg.de (15.11.2022)
Found Exchange server:
Build: 15.1.2507.13
Version: 2016CU23+KB5019077
Build date: 10/2022
Affected by CVE-2022-41040
Affected by CVE-2022-41082
Affected by CVE-2022-41078
Affected by CVE-2022-41123
Affected by CVE-2022-41079
Affected by CVE-2022-41080[via @leakix] #OWASSRF #ProxyNotShell
-
Wie die #HAW #Hamburg geransomwared wurde? Vielleicht so:
haw-mailer.haw-hamburg.de (15.11.2022)
Found Exchange server:
Build: 15.1.2507.13
Version: 2016CU23+KB5019077
Build date: 10/2022
Affected by CVE-2022-41040
Affected by CVE-2022-41082
Affected by CVE-2022-41078
Affected by CVE-2022-41123
Affected by CVE-2022-41079
Affected by CVE-2022-41080[via @leakix] #OWASSRF #ProxyNotShell
-
We have observed exploitation attempts for a new exploit method for Microsoft Exchange Server, #OWASSRF. In all the attempts we observed, threat actors used a PowerShell backdoor, which we track as #SilverArrow.
bit.ly/3WnFbQe -
We have observed exploitation attempts for a new exploit method for Microsoft Exchange Server, #OWASSRF. In all the attempts we observed, threat actors used a PowerShell backdoor, which we track as #SilverArrow.
bit.ly/3WnFbQe -
CrowdStrike published a #PowerShell script for CVE-2022-41080 #OWASSRF that assumes the column headers for the Rpc_Http logs have not been modified from their original order/format.
This is also a useful way to learn PowerShell. Short script, different variable types, formatting and filtering data. Good reference to follow.
-
CrowdStrike published a #PowerShell script for CVE-2022-41080 #OWASSRF that assumes the column headers for the Rpc_Http logs have not been modified from their original order/format.
This is also a useful way to learn PowerShell. Short script, different variable types, formatting and filtering data. Good reference to follow.
-
Ransomware-wielding attackers are using a new exploit chain that includes one of the ProxyNotShell vulnerabilities (CVE-2022-41082) to achieve remote code execution on Microsoft Exchange servers.
The ProxyNotShell exploit chain used CVE-2022-41040, a SSRF vulnerability in the Autodiscover endpoint of Microsoft Exchange, while this new one uses CVE-2022-41080 to achieve privilege escalation through Outlook Web Access (OWA).
https://www.helpnetsecurity.com/2022/12/21/cve-2022-41080/
#Microsoft #Exchange #OWASSRF #vulnerability #exploit #Cybersecurity
-
Ransomware-wielding attackers are using a new exploit chain that includes one of the ProxyNotShell vulnerabilities (CVE-2022-41082) to achieve remote code execution on Microsoft Exchange servers.
The ProxyNotShell exploit chain used CVE-2022-41040, a SSRF vulnerability in the Autodiscover endpoint of Microsoft Exchange, while this new one uses CVE-2022-41080 to achieve privilege escalation through Outlook Web Access (OWA).
https://www.helpnetsecurity.com/2022/12/21/cve-2022-41080/
#Microsoft #Exchange #OWASSRF #vulnerability #exploit #Cybersecurity