This is beautiful because every exchange server has admin to every other exchange server in the environment. With auth coercion, you go from low priv to admin, then a high likelihood of SYSTEM on one Exchange server to AddMember of privileged groups.
One of my favorite paths.
Found out I’ll be speaking @defcon 31! Malware design - abusing legacy Microsoft transports and session architecture. Hope to see you there! #DEFCON#DEFCON31
Just made SpoolSploit(https://t.co/tH2AoSQyjW) public on my GitHub: A collection of Windows print spooler exploits containerized with other utilities for practical exploitation. #printnightmare#spoolsample
@sadhineth Ah I see the issue. Create a folder called “logs” in the “ssploit” directory. This directory is created automatically in my docket build file so if you fun it directly then you have to create that folder.
I waited 2 years for this, rewrote impacket for this, asked cryptographers to remake algos in python for this, spent enormous time of my life to make this happen. and it's finally here this finally works and I can't find the words to express my satisfaction.