Password Spraying Outlook Web Access – How to Gain Access to Domain Credentials Without Being on a Target’s Network: Part 2
ID: 183f1f56-05c7-5e8a-8663-3a7e3b6e3f48
STIX ID: report--183f1f56-05c7-5e8a-8663-3a7e3b6e3f48
Feed Name: Black Hills Infosec Blog
Threat Score
**Executive summary:** This post demonstrates how an attacker can enumerate an organization’s username schema from metadata in publicly posted documents and then perform password-spraying attacks against external domain-authenticating services (such as OWA) using tools like FOCA, Burp Intruder, and Patator; the author describes methodology, shows results from an engagement (130 credentials obtained), and provides mitigations including metadata scrubbing and enforcing MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
