On 29 September 2010 11:07, silky <[email protected]> wrote: > It affects everyone using .NET. >
Everyone using ASP.NET who uses session state/view state etc. If you don't use these things then there is no impact for you. Though this: http://weblogs.asp.net/scottgu/archive/2010/09/18/important-asp-net-security-vulnerability.aspx says: What does the vulnerability enable? *An attacker using this vulnerability can request and download files within an ASP.NET Application like the web.config file (which often contains sensitive data).* At attacker exploiting this vulnerability can also decrypt data sent to the client in an encrypted state (like ViewState data within a page). Has anyone read any more specifics on that part? David. -- *David Connors* | [email protected] | www.codify.com Software Engineer Codify Pty Ltd Phone: +61 (7) 3210 6268 | Facsimile: +61 (7) 3210 6269 | Mobile: +61 417 189 363 V-Card: https://www.codify.com/cards/davidconnors Address Info: https://www.codify.com/contact
