Massive ASP.Net Forms Authentication vulnerability

M

Mike Bridge

This seems to me like an absolutely massive security hole, but I see
it was posted to various security lists TWO WEEKS ago without any
response. What's Microsoft waiting for??
 
M

Mike Bridge

Hmm... this exploit affects URLs for localhost, but I can't seem to
get it to work on a regular URL....

-Mike
 
D

Daniel Fisher\(lennybacon\)

What about installing UrlScan.

I did that a year ago or so....
 
P

Prodip Saha

Greg,
I have confirmed this security hole on XP Professional with IE6. This is a
reminder to the companies- never solely rely on microsoft for their
application security.

Thanks,
Prodip
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Members online

Forum statistics

Threads
473,769
Messages
2,569,579
Members
45,053
Latest member
BrodieSola

Latest Threads

Top