Exchange Multiple Internal IP Disclosures
------------------------------ ------------
Advisory:
http://foofus.net/?p=758
http://www.securitypentest. com/2014/08/exchange-multiple- internal-ip.html
Autodiscover Enumeration Vulnerability
------------------------------ ------------
Advisory:
http://foofus.net/?p=793
http://www.securitypentest. com/2014/08/autodiscover- enumeration-vulnerab
ility.html
CAS Authentication Timing Attack
------------------------------ ------------
Advisory:
http://foofus.net/?p=784
http://www.securitypentest. com/2014/08/cas- authentication-timing-attack.
html
POC video:
http://www.securitypentest. com/2014/08/owa-timing-attack- poc.html
Tools
------------------------------ ------------
http://foofus.net/?p=804
//The information contained within this publication is
//supplied "as-is"with no warranties or guarantees of fitness
//of use or otherwise. Bot24, Inc nor Bradley Sean Susser accepts
//responsibility for any damage caused by the use or misuse of
//this information
------------------------------
Advisory:
http://foofus.net/?p=758
http://www.securitypentest.
Autodiscover Enumeration Vulnerability
------------------------------
Advisory:
http://foofus.net/?p=793
http://www.securitypentest.
ility.html
CAS Authentication Timing Attack
------------------------------
Advisory:
http://foofus.net/?p=784
http://www.securitypentest.
html
POC video:
http://www.securitypentest.
Tools
------------------------------
http://foofus.net/?p=804
//The information contained within this publication is
//supplied "as-is"with no warranties or guarantees of fitness
//of use or otherwise. Bot24, Inc nor Bradley Sean Susser accepts
//responsibility for any damage caused by the use or misuse of
//this information