Output Messenger Web Application


There is a Web application running on the port 14123

Webroot Redirected to a login page

Burp Suite Upstream Proxies


Set

Switching it over to Burp Suite’s proxy

Authentication


During the LDAPDomainDump, I remember seeing a CLEARTEXT credential that belonged to no domain users, yet contains word, “messenger”. It might belong here; k.turner:MessengerApp@Pass!

Successfully Authenticated. The credential was indeed for the web application. Both admin and o.martinez users appear to be online yet, “away”

Chatroom


There are 2 chatrooms

Dev_Chat

The chat goes over a custom application to retrieve user information; UserExplorer.exe It mentions “Output Wall” that contains updates

General_chat

It would appear that there is a dedicated application for Windows