Groups | Blog | Home
all groups > asp.net security > september 2004 >

asp.net security : Massive ASP.Net Forms Authentication vulnerability


Greg Hurlman
9/30/2004 6:17:02 AM
http://sourceforge.net/mailarchive/forum.php?thread_id=5671607&forum_id=24754

This is, IMNSHO, the worst thing I've ever heard of.

Spread the word, test your sites, and send angry emails to Microsoft.
---
Greg Hurlman
ghurlman*AT*squaretwo*DOT*net
Mike Bridge
9/30/2004 5:15:57 PM
This seems to me like an absolutely massive security hole, but I see
it was posted to various security lists TWO WEEKS ago without any
response. What's Microsoft waiting for??




On Thu, 30 Sep 2004 06:17:02 -0700, Greg Hurlman
[quoted text, click to view]
Mike Bridge
9/30/2004 5:47:56 PM
Hmm... this exploit affects URLs for localhost, but I can't seem to
get it to work on a regular URL....

-Mike

On Thu, 30 Sep 2004 06:17:02 -0700, Greg Hurlman
[quoted text, click to view]
Daniel Fisher(lennybacon)
10/1/2004 10:56:43 AM
What about installing UrlScan.

I did that a year ago or so....

--
Daniel Fisher(lennybacon)
MCP C# ASP.NET
Blog: http://www.lennybacon.com/




[quoted text, click to view]

Prodip Saha
10/4/2004 9:39:16 AM
Greg,
I have confirmed this security hole on XP Professional with IE6. This is a
reminder to the companies- never solely rely on microsoft for their
application security.

Thanks,
Prodip

[quoted text, click to view]

AddThis Social Bookmark Button