Home Contact

OAT

OCS Assessment Tool

What is OAT?

OAT is an Open Source Security tool designed to check the password strength of Microsoft Office Communication Server users. After a password is compromised, OAT demonstrates potential UC attacks that can be performed by legitimate users if proper security controls are not in place.

Features

  • Online Dictionary Attack
  • Presence Stealing
  • Contact List Stealing
  • Single User Flood Mode (Internal)
  • Domain Flood Mode (Internal)
  • Call Walk (Internal/External)
  • Play Spam Audio
  • Detailed Report Generation

Authors

OAT attacks in Action

Successful "Online Dictionary Attack" against target user.

SS_FetchUsers

OAT fetching users from target domain

SS_FetchUsers

OAT stealing presence information of fetched users.

SS_FetchUsersPresence

OAT performing "Call Walking Attack" against fetched users.

SS_internalCallWalk

OAT performing "SPAM IM Flooding Attack" against fetched contact list of target user.

SS_ExternalIMFlood

OAT trying to play SPAM Audio file.

SS_ExtPlayFile

Reports Generated by OAT

SS_Reports

About OAT

SS_AboutOAT