Konrad Haase

Understanding the Risks Associated with NTLM Authentication
18 min read

Understanding the Risks Associated with NTLM Authentication

Despite the release of Kerberos more than 20 years ago, many enterprises today have not transitioned away from using NTLM authentication in their...

Read More >
Access Control Facades and Hardcoded Secrets: A Sage 300 Case Study (Part 1)
19 min read

Access Control Facades and Hardcoded Secrets: A Sage 300 Case Study (Part 1)

Software solutions have had to evolve rapidly to keep pace with cybersecurity threats. Today, nearly every significant software solution is loaded...

Read More >
Access Control Facades and Hardcoded Secrets: A Sage 300 Case Study (Part 3)
7 min read

Access Control Facades and Hardcoded Secrets: A Sage 300 Case Study (Part 3)

This is a continuation of the Sage 300 case study series where we explore the process of discovering and developing exploits for six (6) different...

Read More >
Access Control Facades and Hardcoded Secrets: A Sage 300 Case Study (Part 2)
28 min read

Access Control Facades and Hardcoded Secrets: A Sage 300 Case Study (Part 2)

This is a continuation of the Sage 300 case study series where we explore the process of discovering and developing exploits for six (6) different...

Read More >
Critical Vulnerability Disclosure: Sage 300
3 min read

Critical Vulnerability Disclosure: Sage 300

In 2022 Konrad Haase, a member of the Control Gap Offensive Security team, discovered a series of vulnerabilities in Sage 300, a well-established...

Read More >
A PlexTrac Story
16 min read

A PlexTrac Story

Businesses of all sizes have increasingly been developing and deploying complex internet-facing web applications to provide consumers with richer...

Read More >
A Sage 300 Case Study
22 min read

A Sage 300 Case Study

In modern cyberattacks, threat actors will often begin their attacks against enterprises by obtaining low-privileged access to a single system in the...

Read More >