home.social

#owassrf — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #owassrf, aggregated by home.social.

fetched live
  1. Wie die #HAW #Hamburg geransomwared wurde? Vielleicht so:

    haw-mailer.haw-hamburg.de (15.11.2022)

    Found Exchange server:
    Build: 15.1.2507.13
    Version: 2016CU23+KB5019077
    Build date: 10/2022
    Affected by CVE-2022-41040
    Affected by CVE-2022-41082
    Affected by CVE-2022-41078
    Affected by CVE-2022-41123
    Affected by CVE-2022-41079
    Affected by CVE-2022-41080

    [via @leakix] #OWASSRF #ProxyNotShell

  2. Wie die #HAW #Hamburg geransomwared wurde? Vielleicht so:

    haw-mailer.haw-hamburg.de (15.11.2022)

    Found Exchange server:
    Build: 15.1.2507.13
    Version: 2016CU23+KB5019077
    Build date: 10/2022
    Affected by CVE-2022-41040
    Affected by CVE-2022-41082
    Affected by CVE-2022-41078
    Affected by CVE-2022-41123
    Affected by CVE-2022-41079
    Affected by CVE-2022-41080

    [via @leakix] #OWASSRF #ProxyNotShell

  3. We have observed exploitation attempts for a new exploit method for Microsoft Exchange Server, #OWASSRF. In all the attempts we observed, threat actors used a PowerShell backdoor, which we track as #SilverArrow.
    bit.ly/3WnFbQe

  4. We have observed exploitation attempts for a new exploit method for Microsoft Exchange Server, #OWASSRF. In all the attempts we observed, threat actors used a PowerShell backdoor, which we track as #SilverArrow.
    bit.ly/3WnFbQe

  5. CrowdStrike published a #PowerShell script for CVE-2022-41080 #OWASSRF that assumes the column headers for the Rpc_Http logs have not been modified from their original order/format.

    This is also a useful way to learn PowerShell. Short script, different variable types, formatting and filtering data. Good reference to follow.

    github.com/CrowdStrike/OWASSRF

  6. CrowdStrike published a #PowerShell script for CVE-2022-41080 #OWASSRF that assumes the column headers for the Rpc_Http logs have not been modified from their original order/format.

    This is also a useful way to learn PowerShell. Short script, different variable types, formatting and filtering data. Good reference to follow.

    github.com/CrowdStrike/OWASSRF

  7. Ransomware-wielding attackers are using a new exploit chain that includes one of the ProxyNotShell vulnerabilities (CVE-2022-41082) to achieve remote code execution on Microsoft Exchange servers.

    The ProxyNotShell exploit chain used CVE-2022-41040, a SSRF vulnerability in the Autodiscover endpoint of Microsoft Exchange, while this new one uses CVE-2022-41080 to achieve privilege escalation through Outlook Web Access (OWA).

    helpnetsecurity.com/2022/12/21

    #Microsoft #Exchange #OWASSRF #vulnerability #exploit #Cybersecurity

  8. Ransomware-wielding attackers are using a new exploit chain that includes one of the ProxyNotShell vulnerabilities (CVE-2022-41082) to achieve remote code execution on Microsoft Exchange servers.

    The ProxyNotShell exploit chain used CVE-2022-41040, a SSRF vulnerability in the Autodiscover endpoint of Microsoft Exchange, while this new one uses CVE-2022-41080 to achieve privilege escalation through Outlook Web Access (OWA).

    helpnetsecurity.com/2022/12/21

    #Microsoft #Exchange #OWASSRF #vulnerability #exploit #Cybersecurity