<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Owning Outlook Web Access (OWA) users</title>
	<atom:link href="http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: Nitin Kushwaha</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-133918</link>
		<dc:creator>Nitin Kushwaha</dc:creator>
		<pubDate>Thu, 08 Dec 2011 19:02:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-133918</guid>
		<description>Hey Adrian,

I would like to know if any other exploits in EX2k3 OWA with SP2. running on MS W2k3 Sp2. The problem i am facing is the company had implemented the fix for URL redirection: something like, making a copy of OWALogon.asp, then say Re-directing the base URL for OWA to itself.

any clues??</description>
		<content:encoded><![CDATA[<p>Hey Adrian,</p>
<p>I would like to know if any other exploits in EX2k3 OWA with SP2. running on MS W2k3 Sp2. The problem i am facing is the company had implemented the fix for URL redirection: something like, making a copy of OWALogon.asp, then say Re-directing the base URL for OWA to itself.</p>
<p>any clues??</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sillentbot007</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-129313</link>
		<dc:creator>sillentbot007</dc:creator>
		<pubDate>Thu, 09 Dec 2010 17:54:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-129313</guid>
		<description>Is this method still effective anyone?</description>
		<content:encoded><![CDATA[<p>Is this method still effective anyone?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian 'pagvac' Pastor</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-123641</link>
		<dc:creator>Adrian 'pagvac' Pastor</dc:creator>
		<pubDate>Tue, 09 Sep 2008 22:53:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-123641</guid>
		<description>Just tested this attack again successfully on a OWA 2K3 installation during a pentest. It&#039;s good to see it still works!

However, I  would like to know why it doesn&#039;t work on all OWA 2K3 installations. Reading our readers&#039; comments on this post shows that the exploit doesn&#039;t seem to work for everyone. Perhaps there is something configuration-specific that would make this attack not work?</description>
		<content:encoded><![CDATA[<p>Just tested this attack again successfully on a OWA 2K3 installation during a pentest. It&#8217;s good to see it still works!</p>
<p>However, I  would like to know why it doesn&#8217;t work on all OWA 2K3 installations. Reading our readers&#8217; comments on this post shows that the exploit doesn&#8217;t seem to work for everyone. Perhaps there is something configuration-specific that would make this attack not work?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: chrisb</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-121051</link>
		<dc:creator>chrisb</dc:creator>
		<pubDate>Wed, 07 May 2008 10:36:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-121051</guid>
		<description>Hi, Im in quite slow, but explain the get-credentials.php file please. Must I still write this and host it on my website?</description>
		<content:encoded><![CDATA[<p>Hi, Im in quite slow, but explain the get-credentials.php file please. Must I still write this and host it on my website?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jan</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-118289</link>
		<dc:creator>Jan</dc:creator>
		<pubDate>Mon, 07 Apr 2008 17:33:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-118289</guid>
		<description>Ok I have been playing with this all morning and I am stuck.

The server used is OWA2003. I have tried sending it to myself from my private mail doing it a few different ways. Not exactly sure what I am doing wrong. Not sure if it is because I am at home and logging into the OWA from here remotely. Would you be willing to help me out with this? After the victim enters the cred where do I view them at, I post the url, but just get the sign in sheet.

Any help would be very appreciated. I am a bit new to this, but love the challange. Just stuck</description>
		<content:encoded><![CDATA[<p>Ok I have been playing with this all morning and I am stuck.</p>
<p>The server used is OWA2003. I have tried sending it to myself from my private mail doing it a few different ways. Not exactly sure what I am doing wrong. Not sure if it is because I am at home and logging into the OWA from here remotely. Would you be willing to help me out with this? After the victim enters the cred where do I view them at, I post the url, but just get the sign in sheet.</p>
<p>Any help would be very appreciated. I am a bit new to this, but love the challange. Just stuck</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-98236</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Thu, 10 Jan 2008 22:53:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-98236</guid>
		<description>Hey Mike. I just read most of the paper and love it. Very simple yet effective technique. These are the kind of hacks I really love!</description>
		<content:encoded><![CDATA[<p>Hey Mike. I just read most of the paper and love it. Very simple yet effective technique. These are the kind of hacks I really love!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-95912</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Sat, 05 Jan 2008 22:31:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-95912</guid>
		<description>Very cool hack!  I&#039;m not surprised that Microsoft doesn&#039;t take it seriously. I think this flaw can be made even more serious by using flash and the crossdomain.xml file as described in this hack presented at Defcon 15: http://www.defcon.org/images/defcon-15/dc15-presentations/Rios/Whitepaper/dc-15-rios-WP.pdf</description>
		<content:encoded><![CDATA[<p>Very cool hack!  I&#8217;m not surprised that Microsoft doesn&#8217;t take it seriously. I think this flaw can be made even more serious by using flash and the crossdomain.xml file as described in this hack presented at Defcon 15: <a href="http://www.defcon.org/images/defcon-15/dc15-presentations/Rios/Whitepaper/dc-15-rios-WP.pdf" rel="nofollow">http://www.defcon.org/images/d.....ios-WP.pdf</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-88528</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Tue, 18 Dec 2007 21:49:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-88528</guid>
		<description>Hi Raffi, this is the same result we got on 3 different OWA installations. Glad to hear to find this attack as neat as we do!</description>
		<content:encoded><![CDATA[<p>Hi Raffi, this is the same result we got on 3 different OWA installations. Glad to hear to find this attack as neat as we do!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackathology</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-88368</link>
		<dc:creator>hackathology</dc:creator>
		<pubDate>Tue, 18 Dec 2007 14:42:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-88368</guid>
		<description>pretty interesting discovery. Too bad, i cant test it.</description>
		<content:encoded><![CDATA[<p>pretty interesting discovery. Too bad, i cant test it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-87837</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 17 Dec 2007 13:32:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-87837</guid>
		<description>this is exactly what we thought :)</description>
		<content:encoded><![CDATA[<p>this is exactly what we thought :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Raffi</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-87835</link>
		<dc:creator>Raffi</dc:creator>
		<pubDate>Mon, 17 Dec 2007 13:29:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-87835</guid>
		<description>I tested on a client&#039;s OWA server and removed the UID. pretty scary. If you don&#039;t have your status line in view, and looked there, you wouldn&#039;t notice that the logon button points to someplace else. holy spear phishing batman</description>
		<content:encoded><![CDATA[<p>I tested on a client&#8217;s OWA server and removed the UID. pretty scary. If you don&#8217;t have your status line in view, and looked there, you wouldn&#8217;t notice that the logon button points to someplace else. holy spear phishing batman</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-86939</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Sat, 15 Dec 2007 13:40:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-86939</guid>
		<description>@Matt - perhaps you don&#039;t even need &quot;1_multipart_xF8FF_2_&quot; in your case? Best thing is just post the original path of a URL that accesses an attachment, and we&#039;ll show you what to do. Anyway, we&#039;ll be in touch via email.</description>
		<content:encoded><![CDATA[<p>@Matt &#8211; perhaps you don&#8217;t even need &#8220;1_multipart_xF8FF_2_&#8221; in your case? Best thing is just post the original path of a URL that accesses an attachment, and we&#8217;ll show you what to do. Anyway, we&#8217;ll be in touch via email.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-85550</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Wed, 12 Dec 2007 20:05:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-85550</guid>
		<description>Thanks, Adrian. I have all the screen shots ready. I have confirmed that our OWA and Exchange servers in prod are 2003.

Another thing that I have noticed though is that none of my URLs have the &quot;1_multipart_xF8FF_2_&quot; at the beginning of attached file names. Could this be an issue?

P.S. I have tried the URL with this string in front of the attachment name,m but to no avail.</description>
		<content:encoded><![CDATA[<p>Thanks, Adrian. I have all the screen shots ready. I have confirmed that our OWA and Exchange servers in prod are 2003.</p>
<p>Another thing that I have noticed though is that none of my URLs have the &#8220;1_multipart_xF8FF_2_&#8221; at the beginning of attached file names. Could this be an issue?</p>
<p>P.S. I have tried the URL with this string in front of the attachment name,m but to no avail.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-85395</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Wed, 12 Dec 2007 14:45:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-85395</guid>
		<description>@Matt - If you paste the real URL (with domain name hidden for privacy) I should be able to reconstruct the exploit URL. One thing I&#039;m thinking of is that the inbox folder&#039;s name has been customized. In that case you need to use the customized value.

I&#039;ll contact you to see the screenshots. Can&#039;t understand why you get the authentication prompt after you have logged in. What&#039;s described on this post has been tested on 3 different OWA2K3 installations with no problem. It&#039;d be quite useful if other GC readers tested it on their installations.</description>
		<content:encoded><![CDATA[<p>@Matt &#8211; If you paste the real URL (with domain name hidden for privacy) I should be able to reconstruct the exploit URL. One thing I&#8217;m thinking of is that the inbox folder&#8217;s name has been customized. In that case you need to use the customized value.</p>
<p>I&#8217;ll contact you to see the screenshots. Can&#8217;t understand why you get the authentication prompt after you have logged in. What&#8217;s described on this post has been tested on 3 different OWA2K3 installations with no problem. It&#8217;d be quite useful if other GC readers tested it on their installations.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-84833</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Tue, 11 Dec 2007 14:49:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-84833</guid>
		<description>@Adrian - Yes the error is returned when accessing the specially crafted URL. The process is that I get the normal Basic Auth pop-up to enter credentials, enter my valid credentials, and then I get another older looking login page. (Can send you screen shots if interested). Then after entering my creds on this new page (and verifying that the url has not changed and I am still on my companies OWA site), I get the owaauth.dll error.

Let me know if you want screenshots for your review.</description>
		<content:encoded><![CDATA[<p>@Adrian &#8211; Yes the error is returned when accessing the specially crafted URL. The process is that I get the normal Basic Auth pop-up to enter credentials, enter my valid credentials, and then I get another older looking login page. (Can send you screen shots if interested). Then after entering my creds on this new page (and verifying that the url has not changed and I am still on my companies OWA site), I get the owaauth.dll error.</p>
<p>Let me know if you want screenshots for your review.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-84755</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Tue, 11 Dec 2007 11:42:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-84755</guid>
		<description>@djteller - thanks for such kind comment!

@Matt - if the hex string is NOT not a unique variable, but rather a constant, then crafting the exploit URL would become even easier. I&#039;m not sure what you mean by the error. Is this an error generated when accessing the specially-crafted URL?

@maotx - it&#039;d be cool to make it work on OWA2K7 as well. Unfortunately, I don&#039;t have access to a OWA2K7 installation to find out if there is a way to replicate this phishing attack.</description>
		<content:encoded><![CDATA[<p>@djteller &#8211; thanks for such kind comment!</p>
<p>@Matt &#8211; if the hex string is NOT not a unique variable, but rather a constant, then crafting the exploit URL would become even easier. I&#8217;m not sure what you mean by the error. Is this an error generated when accessing the specially-crafted URL?</p>
<p>@maotx &#8211; it&#8217;d be cool to make it work on OWA2K7 as well. Unfortunately, I don&#8217;t have access to a OWA2K7 installation to find out if there is a way to replicate this phishing attack.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-84526</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 10 Dec 2007 23:29:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-84526</guid>
		<description>content disposition attachment can be forced to open inside object elements in some browsers</description>
		<content:encoded><![CDATA[<p>content disposition attachment can be forced to open inside object elements in some browsers</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: maotx</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-84512</link>
		<dc:creator>maotx</dc:creator>
		<pubDate>Mon, 10 Dec 2007 22:54:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-84512</guid>
		<description>Does not work with Exchange 2007.  OWA requires .html attached files be saved to disk first.</description>
		<content:encoded><![CDATA[<p>Does not work with Exchange 2007.  OWA requires .html attached files be saved to disk first.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-84364</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Mon, 10 Dec 2007 16:43:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-84364</guid>
		<description>Just thought I would add a note about the long hex-style string. When I tested this on my corporate OWA installation, I got the exact same string as in your post. I also tested with two other colleagues and they also received the same string.

Although our installation generates an error on the server from owaauth.dll, just thought I would alert you to the string issue.</description>
		<content:encoded><![CDATA[<p>Just thought I would add a note about the long hex-style string. When I tested this on my corporate OWA installation, I got the exact same string as in your post. I also tested with two other colleagues and they also received the same string.</p>
<p>Although our installation generates an error on the server from owaauth.dll, just thought I would alert you to the string issue.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: OWA Fishing attack &#124; Stop ID Thieves</title>
		<link>http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users/comment-page-1/#comment-84349</link>
		<dc:creator>OWA Fishing attack &#124; Stop ID Thieves</dc:creator>
		<pubDate>Mon, 10 Dec 2007 16:20:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/owning-outlook-web-access-owa-users#comment-84349</guid>
		<description>[...] I just love Gnucitizen - this time Adrian Pastor explains how to use an Outlook Web Access design flaw to create a phishing attack.Â  [...]</description>
		<content:encoded><![CDATA[<p>[...] I just love Gnucitizen &#8211; this time Adrian Pastor explains how to use an Outlook Web Access design flaw to create a phishing attack.Â  [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
