Yesterday Microsoft announced a new critical vulnerability CVE-2023-23397, a vulnerability in Microsoft Outlook that allows a threat actor to harvest NTLMv2 hashes via a specifically crafted Outlook appointment. Microsoft state that attackers can exploit this vulnerability by sending an email that triggers automatically when it is retrieved and processed by the Outlook client. This can lead to exploitation BEFORE the email is viewed in the Preview Pane. They also state that this vulnerability is being actively exploited in the wild....

15 March 2023
What's the difference between Authentication, Authorisation and Accounting? (AAA)

Authentication Authentication is saying “I am me”. It validates who you are. When you go to a club and the bouncer stops you and you tell him you’re on the guest list, you then show him your ID and he says “Ahh! You’re that guy, come on in” - that’s Authentication Authorisation Authorisation validates what you claim to be. Going back to the club and the bouncer stops you. You show him your ID....

27 July 2022