On 29 September 2010 11:07, silky <[email protected]> wrote:

> It affects everyone using .NET.
>

Everyone using ASP.NET who uses session state/view state etc. If you don't
use these things then there is no impact for you.

Though this:
http://weblogs.asp.net/scottgu/archive/2010/09/18/important-asp-net-security-vulnerability.aspx

says:

What does the vulnerability enable?

*An attacker using this vulnerability can request and download files within
an ASP.NET Application like the web.config file (which often contains
sensitive data).*

At attacker exploiting this vulnerability can also decrypt data sent to the
client in an encrypted state (like ViewState data within a page).


Has anyone read any more specifics on that part?

David.

-- 
*David Connors* | [email protected] | www.codify.com
Software Engineer
Codify Pty Ltd
Phone: +61 (7) 3210 6268 | Facsimile: +61 (7) 3210 6269 | Mobile: +61 417
189 363
V-Card: https://www.codify.com/cards/davidconnors
Address Info: https://www.codify.com/contact

Reply via email to