sensepost / ruler

A tool to abuse Exchange services

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Question about homepage attack

Soutcast opened this issue · comments

I have a question about the homepage attack. You are still able to set a homepage of your account folder in the "data file properties" inside the Outlook GUI. You are also able to set that folder as the startup folder inside the "options" menu under the "advanced tab" inside the Outlook GUI. Does that mean that you can still use the homepage attack or is there something else I do not understand?

You can set homepage under "Outlook Today".

Hi Soutcast

I'm not seeing the option in Outlook 2016 16.0.4639.1000, can you list your steps to get to that option? It sounds like Outlook isn't patched against the homepage issue.

Steps I took:

  • File -> Account Settings
  • Data Files -> Settings

For Outlook Today, it used to be under the folder properties, but I'm not seeing anything.

Hi @staaldraad,
I am using Outlook 2016 MSO 16.0.4639.1000 32-bit
Steps:

  1. Go to Outlook Today which is the folder with your email address on it
  2. Right click on the folder and select Data File Properties from the drop down menu
  3. You can then set a homepage url under the homepage tab

Hey @Soutcast

I see what you mean... Could you drop my an email at estalmans [at] gmail [.com] or DM on twitter @_staaldraad and we discuss further?

I sent an email to your gmail address