Massive ASP.Net Forms Authentication vulnerability

Discussion in 'ASP .Net Security' started by Greg Hurlman, Sep 30, 2004.

  Greg Hurlman

    Greg Hurlman Guest

    Greg Hurlman, Sep 30, 2004
  Mike Bridge

    Mike Bridge Guest

    This seems to me like an absolutely massive security hole, but I see
    it was posted to various security lists TWO WEEKS ago without any
    response. What's Microsoft waiting for??
    Mike Bridge, Sep 30, 2004
  Mike Bridge

    Mike Bridge Guest

    Hmm... this exploit affects URLs for localhost, but I can't seem to
    get it to work on a regular URL....

    Mike Bridge, Sep 30, 2004
  What about installing UrlScan.

    I did that a year ago or so....
    Daniel Fisher\(lennybacon\), Oct 1, 2004
  Prodip Saha

    Prodip Saha Guest

    I have confirmed this security hole on XP Professional with IE6. This is a
    reminder to the companies- never solely rely on microsoft for their
    application security.

    Prodip Saha, Oct 4, 2004
