{"id":3433,"date":"2021-03-07T15:38:25","date_gmt":"2021-03-07T12:38:25","guid":{"rendered":"http:\/\/www.bilgehangunduz.com\/?p=3433"},"modified":"2021-03-07T19:07:01","modified_gmt":"2021-03-07T16:07:01","slug":"hafnium-exchange-servers-with-0-day-exploits","status":"publish","type":"post","link":"https:\/\/www.bilgehangunduz.com\/index.php\/2021\/03\/07\/hafnium-exchange-servers-with-0-day-exploits\/","title":{"rendered":"HAFNIUM Exchange Servers With 0-Day Exploits"},"content":{"rendered":"\n<p>Yeni \u00c7\u0131kan KB5000871 nolu yamay\u0131 Exchange sunucunuza ge\u00e7meden \u00f6nce  CU seviyesini kulland\u0131\u011f\u0131n\u0131z Exchange s\u00fcr\u00fcm\u00fcne g\u00f6re en son CU seviyesine \u00e7ekmelisiniz.<\/p>\n\n\n\n<p>CU son durum &#8211; 01032021<br>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br>Exchange Server 2010 (SP3)<br>Exchange Server 2013 (CU 23)<br>Exchange Server 2016 (CU 19, CU 18 i\u00e7inde yama \u00e7\u0131kt\u0131.)<br>Exchange Server 2019 (CU 8, CU 7 i\u00e7inde yama \u00e7\u0131kt\u0131.)<\/p>\n\n\n\n<!--more-->\n\n\n\n<p>Zaten Exchange Cu Seviyeniz en sonda ise hemen a\u015fa\u011f\u0131daki linklerden ilgili yamay\u0131 indirip sisteminize uygulaya bilirsiniz.<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table class=\"has-subtle-pale-blue-background-color has-background\"><tbody><tr><td>Exchange Cu seviyesi<\/td><td>KB5000871 \u0130ndirme Linki&nbsp;<\/td><\/tr><tr><td>Exchange Server 2010 Sp3 Y\u00fckl\u00fc Sistemler<\/td><td>https:\/\/www.microsoft.com\/download\/details.aspx?familyid=1928d772-3b23-4aa7-a71e-c8ecf2ab1801<\/td><\/tr><tr><td>Exchange Server 2013 Cu 23 Y\u00fckl\u00fc Sistemler<\/td><td>https:\/\/www.microsoft.com\/download\/details.aspx?familyid=1255ecd7-b187-4839-96c9-1fc5e05df7b6<\/td><\/tr><tr><td>Exchange Server 2016 Cu 18 Y\u00fckl\u00fc Sistemler<\/td><td>https:\/\/www.microsoft.com\/download\/details.aspx?familyid=192fa60f-664a-4f3e-b19f-e295135e469b<\/td><\/tr><tr><td>Exchange Server 2016 Cu 19 Y\u00fckl\u00fc Sistemler<\/td><td>https:\/\/www.microsoft.com\/download\/details.aspx?familyid=31211a48-0cef-462e-bb11-c36440f80bb3<\/td><\/tr><tr><td>Exchange Server 2019 Cu 7 Y\u00fckl\u00fc Sistemler<\/td><td>https:\/\/www.microsoft.com\/download\/details.aspx?familyid=2aadda14-b8aa-4370-a492-0a6818facce8<\/td><\/tr><tr><td>Exchange Server 2019 Cu 8 Y\u00fckl\u00fc Sistemler<\/td><td>https:\/\/www.microsoft.com\/download\/details.aspx?familyid=18c75641-e53d-4979-8d5e-29a80674e41f<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>E\u011fer Exchange Cu Seviyeniz eski ise \u00f6nce kendi Exchange uygun en son CU s\u00fcr\u00fcm\u00fcn\u00fc indirmelisiniz.<\/p>\n\n\n\n<p> <\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table class=\"has-fixed-layout\"><tbody><tr><td>Exchange Cumulative Update<\/td><td>En Son S\u00fcr\u00fcm Cu&nbsp; \u0130ndirme Linki&nbsp;<\/td><\/tr><tr><td>Microsoft Exchange Server 2010 Service Pack 3 (SP3)<\/td><td>https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=36768<\/td><\/tr><tr><td>Microsoft Exchange Server 2013 (KB4489622) Cumulative Update 23<\/td><td>https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=58392<\/td><\/tr><tr><td>Microsoft Exchange Server 2016 (KB4588884) Cumulative Update&nbsp; 19<\/td><td>https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=102532<\/td><\/tr><tr><td>Microsoft Exchange Server 2019 (KB4588885) Cumulative Update&nbsp; 8<\/td><td>https:\/\/www.microsoft.com\/Licensing\/servicecenter\/default.aspx<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Hangi S\u00fcr\u00fcm Exchange Kulland\u0131\u011f\u0131n\u0131z\u0131 kolay bir \u015fekilde Program ekle k\u0131sm\u0131nda g\u00f6re bilirsiniz.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"http:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/cugorme.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"564\" src=\"http:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/cugorme-1024x564.png\" alt=\"\" class=\"wp-image-3443\" srcset=\"https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/cugorme-1024x564.png 1024w, https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/cugorme-300x165.png 300w, https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/cugorme-768x423.png 768w, https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/cugorme.png 1051w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<p>Yada Exchange Y\u00f6netim Konsolunda :<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"http:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Cu23After.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"466\" src=\"http:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Cu23After-1024x466.png\" alt=\"\" class=\"wp-image-3451\" srcset=\"https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Cu23After-1024x466.png 1024w, https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Cu23After-300x137.png 300w, https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Cu23After-768x350.png 768w, https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Cu23After-1536x700.png 1536w, https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Cu23After.png 1539w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<p>Yada Power Shell ile \u00f6\u011frenmek i\u00e7in Komudumuz : <\/p>\n\n\n\n<p>Get-ExchangeServer | Format-List Name,Edition,AdminDisplayVersion<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-bilgehan-k-gunduz wp-block-embed-bilgehan-k-gunduz\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"wp-embedded-content\" data-secret=\"MdF7DymEEW\"><a href=\"http:\/\/www.bilgehangunduz.com\/index.php\/2020\/05\/10\/exchange-cu-ogrenmek\/\">Exchange Cu \/ Build number \u00d6\u011frenmek<\/a><\/blockquote><iframe class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;Exchange Cu \/ Build number \u00d6\u011frenmek&#8221; &#8212; Bilgehan K. G\u00fcnd\u00fcz\" src=\"http:\/\/www.bilgehangunduz.com\/index.php\/2020\/05\/10\/exchange-cu-ogrenmek\/embed\/#?secret=MdF7DymEEW\" data-secret=\"MdF7DymEEW\" width=\"500\" height=\"282\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe>\n<\/div><\/figure>\n\n\n\n<p class=\"has-vivid-red-color has-text-color\">Gelelim en \u00f6nemli konuya KB5000871 Yamas\u0131n\u0131 Nas\u0131l Uygulan\u0131r.<\/p>\n\n\n\n<p>\u00d6rne\u011fimi Exchange 2013 Cu 23 y\u00fckl\u00fc bir sunucuda g\u00f6steriyorum.<\/p>\n\n\n\n<p>1.- Y\u00f6netici Yetkileri ile bir Command Prompt a\u00e7\u0131yoruz.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"http:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Cmda.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"491\" src=\"http:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Cmda-1024x491.png\" alt=\"\" class=\"wp-image-3461\" srcset=\"https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Cmda-1024x491.png 1024w, https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Cmda-300x144.png 300w, https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Cmda-768x368.png 768w, https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Cmda.png 1378w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<p>2.- c:\\1\\ Dizini i\u00e7ine koymu\u015f oldu\u011fumuz EXchange 2013 Cu 23 i\u00e7in uygun olan KB5000871 yamas\u0131n\u0131 \u00e7al\u0131\u015ft\u0131r\u0131yoruz.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"http:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Komut.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Komut.png\" alt=\"\" class=\"wp-image-3462\" width=\"582\" height=\"182\" srcset=\"https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Komut.png 1009w, https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Komut-300x94.png 300w, https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Komut-768x241.png 768w\" sizes=\"(max-width: 582px) 100vw, 582px\" \/><\/a><\/figure>\n\n\n\n<p>3.- Kurulum ekran\u0131 a\u00e7\u0131l\u0131yor. Next diyoruz.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"http:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/YamaOncesi1.png\"><img loading=\"lazy\" decoding=\"async\" width=\"716\" height=\"308\" src=\"http:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/YamaOncesi1.png\" alt=\"\" class=\"wp-image-3464\" srcset=\"https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/YamaOncesi1.png 716w, https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/YamaOncesi1-300x129.png 300w\" sizes=\"(max-width: 716px) 100vw, 716px\" \/><\/a><\/figure>\n\n\n\n<p>5.- Finish diyerek kurulumu bitiriyoruz.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"http:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/YamaSonrasi1.png\"><img loading=\"lazy\" decoding=\"async\" width=\"712\" height=\"304\" src=\"http:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/YamaSonrasi1.png\" alt=\"\" class=\"wp-image-3465\" srcset=\"https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/YamaSonrasi1.png 712w, https:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/YamaSonrasi1-300x128.png 300w\" sizes=\"(max-width: 712px) 100vw, 712px\" \/><\/a><\/figure>\n\n\n\n<p>6.- \u00c7\u0131kan Uyar\u0131 \u00fczerine sistemi yeniden ba\u015flat\u0131yoruz ve kald\u0131\u011f\u0131m\u0131z yerden \u00e7al\u0131\u015fmaya devam ediyoruz \ud83d\ude42<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/www.hakanuzuner.com\/wp-content\/uploads\/2021\/03\/SNAG-0147.jpg\" alt=\"\"\/><\/figure>\n\n\n\n<p>Sisteminiz siz yamalar\u0131 ge\u00e7meden bu a\u00e7\u0131k ile istismar edilmi\u015f mi \u00f6\u011frenmek i\u00e7in  a\u015fa\u011f\u0131daki dosyay\u0131 indirin ve uzant\u0131s\u0131n\u0131 Txt de\u011fil Ps1 yap\u0131n ve Exchange sunucunuzda Windows Powershell girip dosyan\u0131n konumuna gidip &#8221; .\\Test-ProxyLogon.ps1&#8243; \u00e7al\u0131\u015ft\u0131rman\u0131z yeterli olacakt\u0131r.<\/p>\n\n\n\n<div class=\"wp-block-file\"><a href=\"http:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Test-ProxyLogon.txt\">Test-ProxyLogon<\/a><a href=\"http:\/\/www.bilgehangunduz.com\/wp-content\/uploads\/2021\/03\/Test-ProxyLogon.txt\" class=\"wp-block-file__button\" download>\u0130ndir<\/a><\/div>\n\n\n\n<p>Sonu\u00e7:<\/p>\n\n\n\n<p>PS C:\\1> .\\Test-ProxyLogon.ps1<br>This script checks for exploits using the instructions outlined in https:\/\/www.microsoft.com\/security\/blog\/2021\/03\/02\/hafnium-targeting-exchange-servers<\/p>\n\n\n\n<p class=\"has-black-color has-text-color\">Checking for CVE-2021-26855 in the HttpProxy logs<\/p>\n\n\n\n<p class=\"has-vivid-green-cyan-color has-text-color\">No suspicious entries found.<\/p>\n\n\n\n<p>Checking for CVE-2021-26858 in the OABGenerator logs<\/p>\n\n\n\n<p class=\"has-vivid-green-cyan-color has-text-color\">No suspicious entries found.<\/p>\n\n\n\n<p>Checking for CVE-2021-26857 in the Event Logs<\/p>\n\n\n\n<p class=\"has-vivid-green-cyan-color has-text-color\">No suspicious entries found.<\/p>\n\n\n\n<p>Checking for CVE-2021-27065 in the ECP Logs<\/p>\n\n\n\n<p class=\"has-vivid-green-cyan-color has-text-color\">No suspicious entries found.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Yeni \u00c7\u0131kan KB5000871 nolu yamay\u0131 Exchange sunucunuza ge\u00e7meden \u00f6nce CU seviyesini kulland\u0131\u011f\u0131n\u0131z Exchange s\u00fcr\u00fcm\u00fcne g\u00f6re en son CU seviyesine \u00e7ekmelisiniz. CU son durum &#8211; 01032021&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;Exchange Server 2010 (SP3)Exchange Server 2013 (CU 23)Exchange Server 2016 (CU 19, CU 18 i\u00e7inde yama \u00e7\u0131kt\u0131.)Exchange Server 2019 (CU 8, CU 7 i\u00e7inde yama \u00e7\u0131kt\u0131.)<\/p>\n","protected":false},"author":657,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/www.bilgehangunduz.com\/index.php\/wp-json\/wp\/v2\/posts\/3433"}],"collection":[{"href":"https:\/\/www.bilgehangunduz.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bilgehangunduz.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bilgehangunduz.com\/index.php\/wp-json\/wp\/v2\/users\/657"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bilgehangunduz.com\/index.php\/wp-json\/wp\/v2\/comments?post=3433"}],"version-history":[{"count":18,"href":"https:\/\/www.bilgehangunduz.com\/index.php\/wp-json\/wp\/v2\/posts\/3433\/revisions"}],"predecessor-version":[{"id":3475,"href":"https:\/\/www.bilgehangunduz.com\/index.php\/wp-json\/wp\/v2\/posts\/3433\/revisions\/3475"}],"wp:attachment":[{"href":"https:\/\/www.bilgehangunduz.com\/index.php\/wp-json\/wp\/v2\/media?parent=3433"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bilgehangunduz.com\/index.php\/wp-json\/wp\/v2\/categories?post=3433"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bilgehangunduz.com\/index.php\/wp-json\/wp\/v2\/tags?post=3433"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}