记录黑客技术中优秀的内容,传播黑客文化,分享黑客技术精华

ProxyNotRelay - An Exchange Vulnerability Encore

2022-11-11 11:37

In this blog post we will dive into the latest Microsoft Exchange 0-day vulnerability, dubbed #ProxyNotShell, how it relates to other Exchange vulnerabilities and finally demonstrate how ProxyRelay can combined with ProxyNotShell, even with Extended Protection and IIS rewrite rules enabled.

However, before we jump in, I just want to clarify that the patches are now available. If you are running a vulnerable verison of Exchange - stop now and go and install the patches. Do not rely on the mitigations! I also wrote the majority of this post before the patches were released, so please save me the job of doing sed s/\bis\b/\bwas\b/g blog.md!

知识来源: www.ctfiot.com/71965.html

阅读:342377 | 评论:0 | 标签:无

想收藏或者和大家分享这篇好文章→复制链接地址

“ProxyNotRelay - An Exchange Vulnerability Encore”共有0条留言

发表评论

姓名:

邮箱:

网址:

验证码:

黑帝公告 📢

十年经营持续更新精选优质黑客技术文章Hackdig,帮你成为掌握黑客技术的英雄

客黑业创的万千入年:由自富财

❤用费0款退球星,年1期效有员会

🧠富财控掌,知认升提,长成起一💡

标签云 ☁