<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Microsoft Web Exchange</title>
        <description>Maybe somebody heard about this issue... 
when i'm browsing my company's Microsoft WebExchange i see this link

http://www.myCompany.com/exchweb/bin/redir.asp?URL=http://www.site.com
Nice phishing issue, isn't it?

1) search web exchange for company X in using google
2) search email adresses available for this company in using google (or browsing their website)
3) send to this adress a phishing mail... something like
   ****
   Hello, 
   please follow this link to access the new   
   logon web mail interface
   http://www.myCompany.com/exchweb/bin/redir.asp?URL=http://www.hack.com/logon.do

   Your mail administrator
   *****
   And retrieve logon for users (probably the same as network access logon, VOIP,...)</description>
        <link>http://sla.ckers.org/forum/read.php?9,9084,9084#msg-9084</link>
        <lastBuildDate>Tue, 21 May 2013 01:17:09 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,9084,9187#msg-9187</guid>
            <title>Re: Microsoft Web Exchange</title>
            <link>http://sla.ckers.org/forum/read.php?9,9084,9187#msg-9187</link>
            <description><![CDATA[yeap.]]></description>
            <dc:creator>hackathology</dc:creator>
            <category>SPAM</category>
            <pubDate>Sat, 31 Mar 2007 03:47:45 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,9084,9130#msg-9130</guid>
            <title>Re: Microsoft Web Exchange</title>
            <link>http://sla.ckers.org/forum/read.php?9,9084,9130#msg-9130</link>
            <description><![CDATA[Yes of course simple phishing attack :)...<br />
it seems that this issue is a well known issue...<br />
isn't it?]]></description>
            <dc:creator>beaule</dc:creator>
            <category>SPAM</category>
            <pubDate>Fri, 30 Mar 2007 03:04:33 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,9084,9112#msg-9112</guid>
            <title>Re: Microsoft Web Exchange</title>
            <link>http://sla.ckers.org/forum/read.php?9,9084,9112#msg-9112</link>
            <description><![CDATA[That might be interesting to abuse them but mostly that's just like any phishing attack in a lot of ways.  Btw, that function is also vuln to XSS.  :)]]></description>
            <dc:creator>rsnake</dc:creator>
            <category>SPAM</category>
            <pubDate>Thu, 29 Mar 2007 21:14:54 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?9,9084,9084#msg-9084</guid>
            <title>Microsoft Web Exchange</title>
            <link>http://sla.ckers.org/forum/read.php?9,9084,9084#msg-9084</link>
            <description><![CDATA[Maybe somebody heard about this issue... <br />
when i'm browsing my company's Microsoft WebExchange i see this link<br />
<br />
http://www.myCompany.com/exchweb/bin/redir.asp?URL=http://www.site.com<br />
Nice phishing issue, isn't it?<br />
<br />
1) search web exchange for company X in using google<br />
2) search email adresses available for this company in using google (or browsing their website)<br />
3) send to this adress a phishing mail... something like<br />
   ****<br />
   Hello, <br />
   please follow this link to access the new   <br />
   logon web mail interface<br />
   http://www.myCompany.com/exchweb/bin/redir.asp?URL=http://www.hack.com/logon.do<br />
<br />
   Your mail administrator<br />
   *****<br />
   And retrieve logon for users (probably the same as network access logon, VOIP,...)]]></description>
            <dc:creator>beaule</dc:creator>
            <category>SPAM</category>
            <pubDate>Thu, 29 Mar 2007 02:28:48 -0500</pubDate>
        </item>
    </channel>
</rss>
