TechDaddy
No Result
View All Result
  • Home
  • Apps
  • Tech
  • Business
  • Internet
  • Automotive
  • Education
  • Lifestyle
    • Fashion
    • Health
    • Travel
  • Phones
  • Home
  • Apps
  • Tech
  • Business
  • Internet
  • Automotive
  • Education
  • Lifestyle
    • Fashion
    • Health
    • Travel
  • Phones
No Result
View All Result
TechDaddy
No Result
View All Result
Home Internet

A New Improved Workaround to Mitigate the ProxyNotShell Vulnerability

by David
in Internet
proxynotshell vulnerability

This post will explain proxynotshell vulnerability. Microsoft released a new, updated workaround to address the ProxyNotShell vulnerability on October 8th, 2022. For the third time, Microsoft revealed a fresh, modified URL Rewrite rule in a workaround article. The blocking rule in IIS Manager has been changed by Microsoft from “.*autodiscover.json.*Powershell.*” to “(?=.*autodiscover.json)(?=.*powershell).” Users are advised to update the new URL Rewrite rule in accordance with the modification.

To get the same security provided by the URL Rewrite Rule, Microsoft has advised customers to use the newly modified Exchange On-premises Mitigation EOMTv2.ps1 PowerShell tool. Get the most recent version here: EOMTv2.ps1.

A New Improved Workaround to Mitigate the ProxyNotShell Vulnerability

Table of Contents hide
A New Improved Workaround to Mitigate the ProxyNotShell Vulnerability
1. Open IIS Manager on the Exchange server
2. open ‘URL Rewrite’ feature for ‘Autodiscover’ under ‘Default web Site’ in IIS Manager
3. Add a rule Under “URL Rewrite”.
4. Add a new Rule for ‘Request blocking’
5. Update pattern (URL Path) in Request blocking Rule
6. Edit the Conditions for the Inbound rule with the Pattern “.*autodiscover\.json.*PowerShell.*”
7. Update Condition input from {URL} to {Request_URI}

In this article, you can know about A New Improved Workaround to Mitigate the ProxyNotShell Vulnerability here are the details below;

1. Open IIS Manager on the Exchange server

Go to Tools -> Internet Information Services (IIS) Manager in Server Manager.

Also READ  Top 10 Best Xbox 360 Emulator For PC Updated In 2024

To open “IIS Manager” from “Server Manager,” an image (1)

2. open ‘URL Rewrite’ feature for ‘Autodiscover’ under ‘Default web Site’ in IIS Manager

Go to Hostname (this sample’s hostname is EXCH19) -> Sites -> Default Web Site -> Autodiscover in IIS Manager.

Choose “URL Rewrite” from the “IIS” menu. Also check Netflix stuck on loading screen

Click on “Open Feature” under “Actions” in the right-pane.

3. Add a rule Under “URL Rewrite”.

To add a new Inbound rule, click on “Add Rule(s)” under “Actions” under the “URL Rewrite” feature.

A picture to be included as “Add Rule(s)” under “URL Rewrite” (1)

4. Add a new Rule for ‘Request blocking’

Choose “Request blocking” from the list of “Inbound rules” in the Add Rule(s) window. Through the use of specific text patterns in the URL path, query string, HTTP headers, and server variables, a rule will be created to deny client requests. To continue, select “OK.” a graphic designating “Inbound Rule” as “Request Blocking” (1)

5. Update pattern (URL Path) in Request blocking Rule

Update the string “(?=.*autodiscover)(?=.*powershell)” in the “Add Request Blocking Rule” window (excluding quotes). Under Using, choose Regular Expression. Click OK after selecting Abort Request in the How to block section.

6. Edit the Conditions for the Inbound rule with the Pattern “.*autodiscover\.json.*PowerShell.*”

Change the Inbound Rule’s Conditions by adding the Pattern “.*autodiscover.json.*PowerShell.”

Also READ  26 Best 123Anime Alternatives To Watch Anime For Free

“Expand ‘RequestBlockingRule1’ on the ‘URL Rewrite’ page and choose the Rule with the Pattern ‘.*autodiscover.json.*Powershell*’.” and select “Edit” from the “Conditions” menu. A picture for the Inbound rule (1)

Change the URL in the condition input to the REQUEST URI

Change the “Condition input” from “URL” to “REQUEST URI” on the “Edit Condition” page, then click “OK.”

7. Update Condition input from {URL} to {Request_URI}

The Microsoft Exchange Server flaws CVE-2022-41040 and CVE-2022-41082 are linked together to broaden the attack surface; if an attacker uses the first to their advantage, they can also exploit the second. Through the use of exploitation, an attacker can process the execution of malware or even have total control over the compromised system. It is essential to be aware of the new, enhanced fix to mitigate the ProxyNotShell vulnerabilities in order to prevent this exploitation. Also check roku remote not working

We hope that this document will inform you of the updated, improved fix for the two 0-day vulnerabilities in Microsoft Exchange Server known as ProxyNotShell. Share this article and aid in protecting the internet.

Related Posts

Manga Z alternatives
Internet

Top 20 Official Manga Z Alternatives In 2024

July 4, 2024
manga18fxalternatives
Internet

34 Official Manga18FX Alternatives In 2024

July 4, 2024
Handwriting Fonts
Internet

20 Best Handwriting Fonts In Word 2024

July 4, 2024

Latest Posts

  • Top 20 Official Manga Z Alternatives In 2024
  • 34 Official Manga18FX Alternatives In 2024
  • 10 Ways To Maintain Consistent Project Quality
  • 20 Best Handwriting Fonts In Word 2024
  • What Is Polkadot Crypto Is It a Good Investment?
  • Top 34 Official MangaMan Alternatives In 2024
  • Top 13 Gantt Chart Software Of 2024 (Free & Paid)

Popular Articles

  • 21 Sites Like Youngtube In 2024
  • 5 Hiren BootCD Alternatives In 2024
  • Top 10 Best Websites Like Bestgore For Horror Movies
  • Top 30 Best Websites like 123Movies For Streaming Movies
  • 11 Sites Like Filecr In 2024
  • YesMovies Alternatives 26 Sites Watch HD Movies Online
  • Top 10 Best YouTube to WAV Converter Free Downloader
  • Top 23 Official Hdrezka Alternatives In 2024
  • Top 10 Best Online Writing Services In 2024
  • 15 Best Sites to Receive SMS Online for Verification
  • Write For Us
  • Contact us
  • TechBlitz

TechDaddy © Copyright 2021, All Rights Reserved. TheMagazine

No Result
View All Result
  • Home
  • Apps
  • Tech
  • Business
  • Internet
  • Automotive
  • Education
  • Lifestyle
    • Fashion
    • Health
    • Travel
  • Phones

TechDaddy © Copyright 2021, All Rights Reserved. TheMagazine

Go to mobile version