praetorian-inc / proxylogon-exploit

Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.
Apache License 2.0
45 stars 17 forks source link

Exploit aborted due to failure: not-found: No Autodiscover information was found #1

Open 13Ragna37 opened 3 years ago

13Ragna37 commented 3 years ago

Hey Guys,

i tried to exploit my Test LAB but all time same error... tried with IP and FQDN.

If i open autodiscover url it works fine and popup auth

[] Started reverse TCP handler on 192.168.178.240:4444 [] Executing automatic check (disable AutoCheck to override) [] Using auxiliary/scanner/http/exchange_proxylogon as check [+] https://xxx.xxx.xxx.xxx:443 - The target is vulnerable to CVE-2021-26855. [] Scanned 1 of 1 hosts (100% complete) [+] The target is vulnerable. [] https://xxx.xxx.xxx.xxx:443 - Attempt to exploit for CVE-2021-26855 [] https://xxx.xxx.xxx.xxx:443 - Retrieving backend FQDN over RPC request [] Internal server name (mail.xxxx.com [] https://xxx.xxx.xxx.xxx:443 - Sending autodiscover request [-] Exploit aborted due to failure: not-found: No Autodiscover information was found [*] Exploit completed, but no session was created.

thx for help

whr819987540 commented 2 years ago

is this fixed? I met the same problem.

sebch- commented 1 year ago

I'm not sure this is an issue with the exploit. No autodiscover information is probably related to a non-existant email address passed as a parameter of the exploit.