logo

MAPI over HTTP and Mailrule Pwnage

ID: 4ab67763-1796-5dbb-a569-1b69ab716602

STIX ID: report--4ab67763-1796-5dbb-a569-1b69ab716602

Feed Name: SensePost Blog

Threat Score
70/100

Date Published: 2016-09-01

Date Updated: 2026-04-29

...
...

This post demonstrates a practical exploitation technique abusing Exchange MAPI/HTTP and Outlook mail rules to achieve remote code execution (reverse shell) by creating malicious mail rules on a target mailbox. It details protocol analysis, ROP/MAPI structures, autodiscover discovery, a Go-based tool (ruler) to add/delete mail rules, and an optional autodiscover-based brute-force feature to obtain credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.