Bypassing Two-Factor Authentication on OWA & Office365 Portals
ID: 65b5ae40-d157-588d-beeb-9580d010602f
STIX ID: report--65b5ae40-d157-588d-beeb-9580d010602f
Feed Name: Black Hills Infosec Blog
Black Hills Information Security published a technical advisory and PoC showing that Exchange Web Services (EWS) can be used to bypass Outlook Web Access and Office365 multi-factor authentication protections: using the MailSniper tool and valid credentials, an attacker can query the EWS endpoint (Exchange.asmx) to read/search a victim’s mailbox even when OWA is protected by DUO or Azure MFA; the post includes test results, screenshots, mitigation suggestions (restrict EWS, require VPN, or lock down EWS per-user), and a disclosure timeline with Microsoft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
