Compatible Support Forums: OWA Function Allows Unauthenticated User to Enumerate ....

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

OWA Function Allows Unauthenticated User to Enumerate ....

#1 User is offline   Philipp 

  • Pooh-Bah
  • Group: Administrators
  • Posts: 1964
  • Joined: 15-July 99

Posted 07 September 2001 - 10:52 AM

.... Global Address List

Among the functions Outlook Web Access (OWA) in Exchange 5.5 offers is the ability to search the global address list (GAL). By design, this is an authenticated function, implemented as a two-tier architecture - a front tier that provides a user interface and a back-end tier that actually performs the search. However, only the front tier actually checks authentication. An attacker who sent a properly formatted request to the back-end function that actually performs the search could enumerate the GAL without authenticating.

Read more
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users