How can I Exfiltrate Zimbra Emails?
by - Thursday, January 1, 1970 at 12:00 AM
Not enough details to try to help here. Sorry.

#databreach
#RIU
Reply
(October 26, 2022, 08:38 PM)thekilob Wrote: Not enough details to try to help here. Sorry.

That's not need so many details, I have access to the Zimbra of a company and I have access with a RCE. When I try to exfiltrate this emails that stay on a folder named store, I can't exfiltrate because I can't make tcp connections outside of the machine. I wanna know how the persons who exploit this vulnerability, how they exfiltrate the files.
Reply
(October 26, 2022, 08:42 PM)Ramilins Wrote:
(October 26, 2022, 08:38 PM)thekilob Wrote: Not enough details to try to help here. Sorry.

That's not need so many details, I have access to the Zimbra of a company and I have access with a RCE. When I try to exfiltrate this emails that stay on a folder named store, I can't exilftrate because I can make tcp connections outside of the machine. I wanna know how the persons who exploit this vulnerability, how they exfiltrate the files.


Why the fuck would you do it with TCP though? That's so stupid, what a fucking skid.

#databreach
#RIU
Reply
(October 26, 2022, 08:43 PM)thekilob Wrote:
(October 26, 2022, 08:42 PM)Ramilins Wrote:
(October 26, 2022, 08:38 PM)thekilob Wrote: Not enough details to try to help here. Sorry.

That's not need so many details, I have access to the Zimbra of a company and I have access with a RCE. When I try to exfiltrate this emails that stay on a folder named store, I can't exilftrate because I can make tcp connections outside of the machine. I wanna know how the persons who exploit this vulnerability, how they exfiltrate the files.


Why the fuck would you do it with TCP though? That's so stupid, what a fucking skid.

What ur recommendation?
Reply
create a python script and exfil through b64, that's the old and tested method anyway.

Reply
(October 26, 2022, 08:47 PM)0x27 Wrote: create a python script and exfil through b64, that's the old and tested method anyway.


I suppose if I can't do nothing more, I do that. Thanks.
Reply
(October 26, 2022, 08:43 PM)thekilob Wrote:
(October 26, 2022, 08:42 PM)Ramilins Wrote:
(October 26, 2022, 08:38 PM)thekilob Wrote: Not enough details to try to help here. Sorry.

That's not need so many details, I have access to the Zimbra of a company and I have access with a RCE. When I try to exfiltrate this emails that stay on a folder named store, I can't exilftrate because I can make tcp connections outside of the machine. I wanna know how the persons who exploit this vulnerability, how they exfiltrate the files.


Why the fuck would you do it with TCP though? That's so stupid, what a fucking skid.


bru atleast be useful and try to contribute a solution

Reply
(October 26, 2022, 08:52 PM)0x27 Wrote:
(October 26, 2022, 08:43 PM)thekilob Wrote:
(October 26, 2022, 08:42 PM)Ramilins Wrote:
(October 26, 2022, 08:38 PM)thekilob Wrote: Not enough details to try to help here. Sorry.

That's not need so many details, I have access to the Zimbra of a company and I have access with a RCE. When I try to exfiltrate this emails that stay on a folder named store, I can't exilftrate because I can make tcp connections outside of the machine. I wanna know how the persons who exploit this vulnerability, how they exfiltrate the files.


Why the fuck would you do it with TCP though? That's so stupid, what a fucking skid.


bru atleast be useful and try to contribute a solution


There's no point in trying to help someone that stupid, man.

#databreach
#RIU
Reply
(October 26, 2022, 09:00 PM)thekilob Wrote:
(October 26, 2022, 08:52 PM)0x27 Wrote:
(October 26, 2022, 08:43 PM)thekilob Wrote:
(October 26, 2022, 08:42 PM)Ramilins Wrote:
(October 26, 2022, 08:38 PM)thekilob Wrote: Not enough details to try to help here. Sorry.

That's not need so many details, I have access to the Zimbra of a company and I have access with a RCE. When I try to exfiltrate this emails that stay on a folder named store, I can't exilftrate because I can make tcp connections outside of the machine. I wanna know how the persons who exploit this vulnerability, how they exfiltrate the files.


Why the fuck would you do it with TCP though? That's so stupid, what a fucking skid.


bru atleast be useful and try to contribute a solution


There's no point in trying to help someone that stupid, man.


Srry, Mr Robot
Reply


 Users viewing this thread: How can I Exfiltrate Zimbra Emails?: No users currently viewing.