Exchange services
Theory
Practice
Enumeration
Discover Exchange Servers
$ cat subdomains.txt
sub1.example.com
sub2.example.ru
sub3.example.bz
$ for i in `cat subdomains.txt | rev | cut -d. -f1-2 | rev | sort -u`; do echo https://autodiscover.$i; done | httpx -silent -random-agent -fr -t 20 -sc -title -td -ip | grep Outlook | grep -oP '\d+\.\d+\.\d+\.\d+' | dnsx -silent -re -ptr
1.3.3.7 [mx1.example.com]
66.66.66.66 [mx2.example.ru]
123.123.123.123 [mx3.example.bz]Enumerate Exchange Version
User Enumeration (GAL)
Vulnerabilities
PrivExchangeProxyLogonProxyShellProxyNotShellPassword Spray
Resources
Last updated