Posts

Showing posts with the label Microsoft Exchange Service Abuse: Ruler

Microsoft Exchange Service Abuse: Ruler

Image
Microsoft Exchange Service Abuse     Ruler is a tool that allows you to interact with Exchange servers through the MAPI/HTTP protocol. The main aim is abuse the client-side Outlook mail rules. “Silentbreak did a great job with this attack and it has served us well. The only downside has been that it takes time to get setup. Cloning a mailbox into a new instance of Outlook can be time consuming. And then there is all the clicking it takes to get a mailrule created. Wouldn’t the command line version of this attack be great? And that is how Ruler was born.” What does it do? Ruler has multiple functions and more are planned. These include Enumerate valid users View currently configured mail rules Create new malicious mail rules Delete mail rules Dump the Global Address List (GAL) VBScript execution through forms     Ruler attempts to be semi-smart when it comes to interacting with Exchange and uses the Autodiscover service (just as your Outlook client would) to discover ...