Back to services
directory443/tcp

Exchange / OWA Attacks

ExchangeOWAExchange ServerOutlook Web Access

Microsoft Exchange is a mail server commonly targeted via OWA, ECP, and Autodiscover. ProxyShell, ProxyLogon, and other CVEs allow RCE and email access.

Ports

PortProtocolDescription
443tcpOWA/ECP HTTPS
80tcpOWA HTTP
25tcpSMTP
587tcpSMTP submission

Fingerprints

Banner / ProbeExpected Response
nmap -sV -p <port> <target>Service banner and version info
nc -nv <target> <port>Raw banner grab

Key Files

PathDescription
C:\Windows\NTDS\ntds.ditAD database with all password hashes
C:\Windows\System32\config\SAMLocal SAM password hashes
C:\Windows\System32\config\SYSTEMSystem hive (boot key for hash decryption)
C:\Windows\System32\config\SECURITYSecurity policy and cached domain credentials
%USERPROFILE%\AppData\Roaming\Microsoft\Credentials\Saved Windows credentials

Default Credentials

UsernamePasswordContext
adminadminGeneric admin account
rootrootGeneric root account

Known CVEs

IdentifierTypeDescription
CVE-2021-26855RCEProxyLogon — SSRF + auth bypass
CVE-2021-34473RCEProxyShell — pre-auth RCE

Exploitation Primitives

TechniqueTool / CommandResult
Reconnmap -sV -sC -p- <target>Full port/service scan
Enumerationnmap --script <service>-* -p <port> <target>Service-specific NSE scripts

Notes

Always start with full port scan: `nmap -sV -sC -p- <target>`.

Check for default credentials before brute-forcing.

Use service-specific NSE scripts: `nmap --script <service>-* -p <port> <target>`.

Remember to check both IPv4 and IPv6 if applicable.

Seen on

ShodanCensysFOFAZoomEye

References