HomeSecurityMicrosoft OWA Server Hacked | 11,000 Passwords Stolen

Microsoft OWA Server hacked | 11,000 passwords stolen

Microsoft OWA Server
Microsoft OWA Server Hacked – 11,000 Passwords Stolen

 

A malicious DLL was able to read and record passwords in plain text format

An unprecedented hacking attack against Microsoft's Outlook (OWA) allowed attackers to capture and steal authentication credentials via a malicious DLL file, which was placed on the server and acted as a backdoor.

The attack was uncovered by experts from Cybereason, when the latter was called in to investigate suspicious activity detected on the OWA server by the IT staff of the company to which the server belongs.

Microsoft Outlook Web Application, or OWA, is essentially an Internet-facing webmail server, which is used by private companies to develop their own email services.

 

Hackers injected a malicious DLL into the OWA server. All user credentials were recorded and sent to the attackers.

As Cybereason experts explain, the attackers replaced OWAAUTH.dll (which is used by OWA as part of the authentication mechanism) with an identical file that contained a backdoor. The malicious DLL collected information about the Active Directory server’s authentication processes, as well as all HTTPS-protected server requests, including login credentials, after decrypting them. This way, the hackers received all the login information/data in plain text.

The hackers who carried out the attack had also taken measures to prevent the backdoor they had installed from being removed, creating an IIS (Microsoft's Web server) filter through which the malicious version of the OWAAUTH.dll file was loaded every time the server was restarted.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS