Light

Episode #838 Quiz

Autodiscover.fiasco
Date: 2021-09-28 | Length: 1.5 hrs | Episode page at twit.tv

About this episode

Chrome’s 12th zero-day of 2021 fixed a use-after-free in the Portals API, while Apple patched actively exploited iOS/macOS flaws, including a kernel type-confusion bug and WebKit-related attacks. Guardicore showed Outlook’s Autodiscover can leak Windows credentials via HTTP fallback and domain collision, prompting Microsoft domain registration mitigations.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what was the key consequence of the malformed certificate technique used by OpenSUpdater on Windows systems?
Question 2: What was the specific protocol downgrade behavior Guardicore described in the Autodiscover research?
Question 3: Which pair of Autodiscover-related applications did the episode say were both involved in the credential leak observed by Guardicore?
Question 4: What limitation of Microsoft's newly updated PC Health Check Tool did Steve identify in the episode?
Question 5: What did Microsoft say was the remediation path for the Patch Tuesday issue affecting apps when EAF was enabled?
Cancel