Exchange your privileges for Domain Admin privs by abusing Exchange
MIT License
POC tools accompanying the blog Abusing Exchange: One API call away from Domain Admin.
These tools require impacket. You can install it from pip with pip install impacket
, but it is recommended to use the latest version from GitHub.
This tool simply logs in on Exchange Web Services to subscribe to push notifications. This will make Exchange connect back to you and authenticate as system.
Attack module that can be used with ntlmrelayx.py to perform the attack without credentials. To get it working:
httpattack.py
to point to the attacker's server where ntlmrelayx will rungit clone https://github.com/SecureAuthCorp/impacket
/impacket/impacket/examples/ntlmrelayx/attacks/
directory.cd impacket
pip install . --upgrade
or pip install -e .