Top 10 winner
A New Attack Surface on MS Exchange - ProxyLogon
Microsoft Exchange splits request handling between a frontend Client Access Service and a backend that trusts frontend-supplied headers, and a static-resource handler took its backend target straight from a client cookie. Chaining that pre-auth SSRF with a post-auth arbitrary file write gives unauthenticated remote code execution on Exchange through port 443, the chain named ProxyLogon.
Record
- Researcher
- Orange Tsai
- Published by
- Orange Tsai
- Date
In the archive
Related sources
- Part 2: ProxyOracle
- Part 3: ProxyShell
- Part 4: ProxyRelay (2022)
- ProxyLogon demonstration
- Talk recording
- Talk recording
Tags
This page is the archive's own catalogue record. The research is the work of Orange Tsai, first published at the original source. Preserved copies are kept so the citation survives its host.