TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Black Hills InfoSec

Bypassing Two-Factor Authentication on OWA & Office365 Portals

BHIS · 2016-11-02 · Read original ↗

ATT&CK techniques detected

7 predictions
T1556.006Multi-Factor Authentication
94%
“bypassing two - factor authentication on owa & office365 portals bypassing two - factor authentication on owa & office365 portals beau bullock / / advisory : the techniques and tools referenced within this blog post may be outdated and do not apply to current situations. however,…”
T1114.002Remote Email Collection
92%
“##chhostname ’ option. if no ‘ - exchhostname ’ option is specified invoke - selfsearch will attempt to autodiscover the mail server. secondly, a valid set of user credentials must be gathered. for some ideas on doing this remotely see this blog post. once the exchange server hos…”
T1556.006Multi-Factor Authentication
84%
“it was an awesome talk that i highly recommend checking out. during his talk nick received a question from the audience in regards to whether two - factor authentication ( 2fa ) would stop the attacks he mentioned during the talk. nick replied with a statement i found very intere…”
T1556.006Multi-Factor Authentication
74%
“in conclusion, it appears that outlook portals that are being protected by two - factor authentication might not be covering all of the authentication protocols to microsoft exchange. in this post it was demonstrated that exchange web services is not being protected by a popular …”
T1114.002Remote Email Collection
66%
“is a problem in which microsoft exchange server exposes the exchange web services interface unprotected by 2fa alongside owa. update as of additionally, a very detailed post regarding the various protocols of exchange has been put together here : http : / / exchangeserverpro. com…”
T1556.006Multi-Factor Authentication
43%
“s inbox for key terms ( by default “ * pass * ”, “ * creds * ”, and “ * credentials * ” ). i tested this against the account that was setup to be protected by duo 2fa. mailsniper was able to successfully read and search through emails of this account completely bypassing the two …”
T1111Multi-Factor Authentication Interception
31%
“in conclusion, it appears that outlook portals that are being protected by two - factor authentication might not be covering all of the authentication protocols to microsoft exchange. in this post it was demonstrated that exchange web services is not being protected by a popular …”

Summary

Beau Bullock // Full Disclosure: Black Hills Information Security believes in responsible disclosure of vulnerabilities. This vulnerability was reported to Microsoft on September 28th, 2016. As of the publication date of […]

The post Bypassing Two-Factor Authentication on OWA & Office365 Portals appeared first on Black Hills Information Security, Inc..