Forum Discussion

rockbd's avatar
rockbd
Copper Contributor
Dec 15, 2021

How to mitigate this Owowa credential stealer and remote access panel.

Hi All

 

Today, I got the following article describing the problem but not the solution. Can anyone know how to protect the Exchange OWA from this problem?

 

https://securelist.com/owowa-credential-stealer-and-remote-access/105219/

 

I am using MS Exchange 2016, and OWA is published with WAF.

 

Thanks in advance.

 

2 Replies

  • justinsiegard's avatar
    justinsiegard
    Copper Contributor
    Just reading this myself an trying to understand if there's anything hybrid users need to do. I think we are ok as all of our mailboxes are hosted in Exchange online, our on premise servers are only for SMTP relays and management but I'm a little unclear.