Autodiscovering your credentials

3 views
Skip to first unread message

Kurt Buff

unread,
Sep 24, 2021, 2:52:59 PM9/24/21
to ntsys...@googlegroups.com, ntexc...@googlegroups.com

Michael B. Smith

unread,
Sep 24, 2021, 2:55:34 PM9/24/21
to ntsys...@googlegroups.com, ntexc...@googlegroups.com

It’s a crock.

 

There is probably SOME client – but it isn’t Outlook – that behaves as he describes. But it’s none of the major clients. And he does a great disservice by showing a partial log where the client identifies itself as Outlook, but it isn’t Outlook.

--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/CADy1Ce5ywY%3DzoS8%3DxD0tTy4jO2VYMc05JY1_8t9VXmogc3oK%2Bg%40mail.gmail.com.

Kurt Buff

unread,
Sep 24, 2021, 2:58:36 PM9/24/21
to ntexc...@googlegroups.com
I'll believe you over them, but that's an awful lot of credentials to grab, so whatever client that might be, it's not completely unknown.

Kurt

You received this message because you are subscribed to the Google Groups "ntexchange" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntexchange+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntexchange/a5954dc9ea304b06842399e244fdd7d4%40smithcons.com.

Michael B. Smith

unread,
Sep 24, 2021, 3:04:41 PM9/24/21
to ntexc...@googlegroups.com

Well, “we” weren’t able to identify a client that behaves this way (Outlook on any platform, Mail.App on MacOS or iOS, or Android Mail).

 

Yes, there are lots of other clients.

Bonnie Pohlschneider

unread,
Sep 24, 2021, 3:05:09 PM9/24/21
to ntexc...@googlegroups.com

Sophos just put out an article on the same thing this week. They even call out that they’re not sure about the client “According to Guardicore, however, in their tests – perhaps conducted with an older version of Windows and Outlook, but we’re not sure”.

 

https://nakedsecurity.sophos.com/2021/09/23/how-outlook-autodiscover-could-leak-your-passwords-and-how-to-stop-it/

 

 

Bonnie Pohlschneider
Information Technology Director, CRSI
Phone 937-653-1317Fax 937-653-1321
www.crsi-oh.com

Kurt Buff

unread,
Sep 24, 2021, 3:39:10 PM9/24/21
to ntexc...@googlegroups.com
An excellent follow-up (rebuttal?) to the Guardicore report. Thanks for this.

Kurt

Reply all
Reply to author
Forward
0 new messages