Hacked Microsoft Outlook Web Application (OWA)

An attack on Microsoft's Outlook Web Application (OWA) allowed hackers to obtain login credentials through a malicious DLL file they were able to load on the server.Outlook Web Application

The attack was revealed by Cybereason security company when Microsoft requested its services.

Microsoft's Outlook Web Application (OWA) is an online webmail server, which exists as of Microsoft . Exchange Server allows companies as well as individuals to run the operating system to develop their own electronic services U.

As Cybereason security company explains, attackers replaced OWAAUTH.dll with one that contained a backdoor. So they were able to collect information from the local Directory Server authentication procedures (a server that manages the common authentication procedures).

So while all the authentication procedures were working correctly on the Outlook Web Application server using SSL / TLS encryption, the DLL file allowed hackers to obtain all the sign-in information in plain text format after the DLL has access before the encryption stage.

All recorded data was stored in a log.txt file on the server. Her researchers Cybereason discovered more than 11.000 user names and passwords in this file. The company running the OWA server has about 19.000 employees.

Hackers are reportedly taking measures to prevent the attack from being revealed, but if the backdoor is found to be difficult to remove. They created a filter on IIS (Microsoft Web Server) through which they uploaded the malicious OWAAUTH.dll file whenever the server was restarted.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).