OWA
Outlook Web Access
Enumerate Users
Authentication Request | Kerberos Process | Response Time |
---|---|---|
Non-existing realm | KDC searches for realm | 2-3 seconds |
Realm exists but username does not exist | Pre-authentication ticket created to verify username | 5-60 seconds |
Realm and username exists | Pre-authentication ticket created to verify password | < 2 seconds |
"Responses in different environments may have different response times but the pattern in the timing response behavior still exist." (ref)
MSF
MailSniper
Password Spray
Ruler
Autodiscover URL implicit:
Autodiscover URL explicit:
Notes:
In users.txt there's only "username" on a line, not "DOMAIN\username".
Errors like
ERROR: 04:27:43 brute.go:193: An error occured in connection - Get https://autodiscover.megacorp.com/autodiscover/autodiscover.xml: Get https://autodiscover.megacorp.com/autodiscover/autodiscover.xml: net/http: request canceled
do not affect the current password probe.
Enumerate NTLM
Nmap
MSF
MailSniper
Last updated