Skip to content

Conversation

EsadCetiner
Copy link
Member

Removes the .application extension from the restricted file extension list. I found this via an attack in my logs, but I don't think this attack should be blocked because of the file extension. As far as I can tell accessing this endpoint is perfectly legitimate, it has something to do with OWA and exports.

GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application

Copy link
Contributor

📊 Quantitative test results for language: eng, year: 2023, size: 10K, paranoia level: 1:
🚀 Quantitative testing did not detect new false positives

@EsadCetiner EsadCetiner added this pull request to the merge queue Apr 22, 2025
Merged via the queue into coreruleset:main with commit 943a621 Apr 22, 2025
6 checks passed
@EsadCetiner EsadCetiner deleted the fix-remove-application-extension branch April 22, 2025 10:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants