Exchange Server and Office 365: Access to attachments and images possible without authentication

Under certain circumstances, Microsoft Office 365 and Exchange Server allow access to attachments and images in emails without the need for authentication. In most cases it should be difficult to exploit this problem, but reader L. Herzog writes to me that this problem could be exploited in his environment. L. Herzog has ... Read more

HowTo: Installing and configuring OCSP on Windows Server 2022 (online responder)

This short HowTo is about the configuration of OCSP (Online Certificate Status Protocol) or the "Online Responder" role on Windows Server 2022. OCSP (Online Certificate Status Protocol) is a protocol that is used within the PKI. It enables the status of certificates to be checked in real time. Instead of checking the validity of certificates in long revocation lists (Certificate Revocation ... Read more

CVE-2024-21410: Exchange vulnerability is actively exploited

The critical vulnerability CVE-2024-21410 in Exchange Server, which was made public on February 13, 2024, is now being actively exploited. The vulnerability CVE-2024-21410 allows attackers to perform an NTLM relay attack (pass the hash). In this case, attackers can trick a client such as Outlook into logging on to a malicious relay in order to obtain the NTLM credentials. The ... Read more

Exchange 2019: Mainstream support ends today

Today, mainstream support for Exchange Server 2019 has expired, so both Exchange Server versions that are still supported are now in extended support, which ends on October 14, 2025. While Exchange 2016 will only receive security updates, Exchange 2019 will receive two more CUs. The CU14 for Exchange 2019 will be released soon and CU15 will also be ... Read more

Merry Christmas!

I wish all friends, readers and supporters a merry and peaceful Christmas, take care of yourselves and stay healthy. I wish all admins who are looking after the well-being of the systems during or between the holidays every success. Take a few days off as soon as possible and treat yourselves and your loved ones to something nice. ... Read more

Internal ACME certification authority for the automation of certificates

Most people will know Let's Encrypt as a free and open certification authority. Let's Encrypt uses the ACME (Automatic Certificate Management Environment) protocol to issue valid certificates for all kinds of services and systems with minimal administrative effort. Let's Encrypt is particularly suitable for all systems and services that are publicly accessible, as the issuing process for ... Read more

IONOS discontinues Smarthost function as of 15.01.2024

I am currently receiving a lot of inquiries about Exchange Server and sending emails via IONOS. As of January 15, 2024, IONOS will discontinue the smarthost function for IONOS mailboxes, which in turn means that Exchange servers can no longer use IONOS as a smarthost. Further information from IONOS can be found here: Apparently, there are quite a lot of people who are affected by this ... Read more