I thought Scott Guthrie's post, which you referred to, has updates and references (links) that substantiated that statement?
_____ Ian Thomas Victoria Park, Western Australia _____ From: [email protected] [mailto:[email protected]] On Behalf Of David Connors Sent: Wednesday, September 29, 2010 10:16 AM To: [email protected]; ozDotNet Subject: Re: IMPORTANT - ASP.NET update and security advisory On 29 September 2010 11:07, silky <[email protected]> wrote: It affects everyone using .NET. Everyone using ASP.NET who uses session state/view state etc. If you don't use these things then there is no impact for you. Though this: http://weblogs.asp.net/scottgu/archive/2010/09/18/important-asp-net-security -vulnerability.aspx says: What does the vulnerability enable? An attacker using this vulnerability can request and download files within an ASP.NET Application like the web.config file (which often contains sensitive data). At attacker exploiting this vulnerability can also decrypt data sent to the client in an encrypted state (like ViewState data within a page). Has anyone read any more specifics on that part? David. -- David Connors | <mailto:[email protected]> [email protected] | <http://www.codify.com> www.codify.com Software Engineer Codify Pty Ltd Phone: +61 (7) 3210 6268 | Facsimile: +61 (7) 3210 6269 | Mobile: +61 417 189 363 V-Card: <https://www.codify.com/cards/davidconnors> https://www.codify.com/cards/davidconnors Address Info: <https://www.codify.com/contact> https://www.codify.com/contact
