{"id":10664,"date":"2022-07-08T02:23:04","date_gmt":"2022-07-08T02:23:04","guid":{"rendered":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/?post_type=session&#038;p=10664"},"modified":"2023-05-26T08:12:44","modified_gmt":"2023-05-26T08:12:44","slug":"how-ntlm-relay-ruins-your-exchange-servers","status":"publish","type":"session","link":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/session\/how-ntlm-relay-ruins-your-exchange-servers\/","title":{"rendered":"How NTLM Relay Ruins Your Exchange Servers"},"content":{"rendered":"<p style=\"text-align: justify;\">NTLM Relay is a classic attack against Windows systems. Although proposed many years ago, it is still a hot topic among red teams, especially in Active Directory environments. Exchange Server, as the most widely used mail server in the world, has also attracted more and more attention from attackers, many Exchange 0days with great impact have been found and even exploited in the wild in recent years.<\/p>\n<p style=\"text-align: justify;\">What will happen when Exchange Server meets with NTLM Relay?<\/p>\n<p style=\"text-align: justify;\">In this talk,<strong> I will uncover a rarely known NTLM relay attack surface of Exchange Server.<\/strong> This attack surface is an architectural design issue in Exchange cluster environment, which <strong>affects about 60% of the Exchange frontend endpoints and 70% of the Exchange backend endpoints. <\/strong>By exploiting these vulnerabilities, attackers can take over any Exchange user&#8217;s mailbox and have the power to read emails, send emails, download attachments, and more. <strong>Some of these vulnerabilities can result in RCE on Exchange Server.<\/strong><\/p>\n<p style=\"text-align: justify;\">I&#8217;ll walk you through all these vulnerabilities in this talk, including their root causes, how to exploit them, patches, and patch bypasses, and what you can do to protect your Exchange Servers.<\/p>\n","protected":false},"template":"","class_list":["post-10664","session","type-session","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How NTLM Relay Ruins Your Exchange Servers - HITBSecConf2024 - Abu Dhabi<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/session\/how-ntlm-relay-ruins-your-exchange-servers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How NTLM Relay Ruins Your Exchange Servers - HITBSecConf2024 - Abu Dhabi\" \/>\n<meta property=\"og:description\" content=\"NTLM Relay is a classic attack against Windows systems. Although proposed many years ago, it is still a hot topic among red teams, especially in Active Directory environments. Exchange Server, as the most widely used mail server in the world, has also attracted more and more attention from attackers, many Exchange 0days with great impact [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/session\/how-ntlm-relay-ruins-your-exchange-servers\/\" \/>\n<meta property=\"og:site_name\" content=\"HITBSecConf2024 - Abu Dhabi\" \/>\n<meta property=\"article:modified_time\" content=\"2023-05-26T08:12:44+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/session\/how-ntlm-relay-ruins-your-exchange-servers\/\",\"url\":\"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/session\/how-ntlm-relay-ruins-your-exchange-servers\/\",\"name\":\"How NTLM Relay Ruins Your Exchange Servers - HITBSecConf2024 - Abu Dhabi\",\"isPartOf\":{\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/#website\"},\"datePublished\":\"2022-07-08T02:23:04+00:00\",\"dateModified\":\"2023-05-26T08:12:44+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/session\/how-ntlm-relay-ruins-your-exchange-servers\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/session\/how-ntlm-relay-ruins-your-exchange-servers\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/session\/how-ntlm-relay-ruins-your-exchange-servers\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Session\",\"item\":\"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/session\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"How NTLM Relay Ruins Your Exchange Servers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/#website\",\"url\":\"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/\",\"name\":\"HITBSecConf2024 - Abu Dhabi\",\"description\":\"Nov 25 - 28, Abu Dhabi, UAE\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How NTLM Relay Ruins Your Exchange Servers - HITBSecConf2024 - Abu Dhabi","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/session\/how-ntlm-relay-ruins-your-exchange-servers\/","og_locale":"en_US","og_type":"article","og_title":"How NTLM Relay Ruins Your Exchange Servers - HITBSecConf2024 - Abu Dhabi","og_description":"NTLM Relay is a classic attack against Windows systems. Although proposed many years ago, it is still a hot topic among red teams, especially in Active Directory environments. Exchange Server, as the most widely used mail server in the world, has also attracted more and more attention from attackers, many Exchange 0days with great impact [&hellip;]","og_url":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/session\/how-ntlm-relay-ruins-your-exchange-servers\/","og_site_name":"HITBSecConf2024 - Abu Dhabi","article_modified_time":"2023-05-26T08:12:44+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/session\/how-ntlm-relay-ruins-your-exchange-servers\/","url":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/session\/how-ntlm-relay-ruins-your-exchange-servers\/","name":"How NTLM Relay Ruins Your Exchange Servers - HITBSecConf2024 - Abu Dhabi","isPartOf":{"@id":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/#website"},"datePublished":"2022-07-08T02:23:04+00:00","dateModified":"2023-05-26T08:12:44+00:00","breadcrumb":{"@id":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/session\/how-ntlm-relay-ruins-your-exchange-servers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/conference.hitb.org\/hitbsecconf2024auh\/session\/how-ntlm-relay-ruins-your-exchange-servers\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/session\/how-ntlm-relay-ruins-your-exchange-servers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/"},{"@type":"ListItem","position":2,"name":"Session","item":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/session\/"},{"@type":"ListItem","position":3,"name":"How NTLM Relay Ruins Your Exchange Servers"}]},{"@type":"WebSite","@id":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/#website","url":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/","name":"HITBSecConf2024 - Abu Dhabi","description":"Nov 25 - 28, Abu Dhabi, UAE","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/wp-json\/wp\/v2\/session\/10664"}],"collection":[{"href":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/wp-json\/wp\/v2\/session"}],"about":[{"href":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/wp-json\/wp\/v2\/types\/session"}],"version-history":[{"count":1,"href":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/wp-json\/wp\/v2\/session\/10664\/revisions"}],"predecessor-version":[{"id":12034,"href":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/wp-json\/wp\/v2\/session\/10664\/revisions\/12034"}],"wp:attachment":[{"href":"https:\/\/conference.hitb.org\/hitbsecconf2024auh\/wp-json\/wp\/v2\/media?parent=10664"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}