Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Legacy and Basic Authentication #6

Open
Zamanry opened this issue Jun 9, 2022 · 2 comments
Open

Legacy and Basic Authentication #6

Zamanry opened this issue Jun 9, 2022 · 2 comments

Comments

@Zamanry
Copy link

Zamanry commented Jun 9, 2022

With Microsoft's off/on intentions to disable legacy and basic authentication methods, is it possible to add support to check for legacy and basic authentication support? These methods do not allow MFA requirements and would fit well with the tool. I understand that you can connect via other methods and see if it is supported, but this is not automated.

To be clear, this is not my area of expertise; so I may be lacking in some of my understanding here. Hence let me know if I am missing something.

@lampnout
Copy link

Hi @Zamanry,

To check for legacy authentication protocols on O365, threat actors are using the user agent "BAV2ROPC". MFASweep could be updated to support this custom user agent.

Regards

@Zamanry
Copy link
Author

Zamanry commented Aug 25, 2022

Nice find! Also, looks like Microsoft is fully removing Basic Authentication in Exchange Online. They previously had disabled it by default, but didn't remove the feature which had some people enabling it again. https://docs.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/deprecation-of-basic-authentication-exchange-online

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants