-
Re: Reported Zero-day Vulnerabilities in Microsoft Exchange Server on 29 Sept. 2022
Yes Norm we lock our Autodiscover down just to the xml file. Here is what we originally had: ../autodiscover/autodiscover.xml /owa /owa/* /ecp/* /ews/* /mapi/* /microsoft-server-activesync* /oab/* Fi… (View Post)1 -
Re: Reported Zero-day Vulnerabilities in Microsoft Exchange Server on 29 Sept. 2022
We already had Request Method "options" in ours. We did have to add several Content Types to get everything to work. I attached the xml export of what we are using now. (View Post)1 -
Re: Microsoft Active Protections Program
I read that as well, but at least the members of that group at least some that I heard about had IPS signatures available the same day MS released the patches. (View Post)1 -
Re: Exchange zero day and WG reverse proxy
Yes the IPS updates are really too slow. It also would have been nice if Microsoft had gotten together with firewall vendors back in January to try to create mitigation for this. (View Post)1