I thought Scott Guthrie's post, which you referred to, has updates and
references (links) that substantiated that statement? 

 

  _____  

Ian Thomas
Victoria Park, Western Australia

  _____  

From: [email protected] [mailto:[email protected]]
On Behalf Of David Connors
Sent: Wednesday, September 29, 2010 10:16 AM
To: [email protected]; ozDotNet
Subject: Re: IMPORTANT - ASP.NET update and security advisory

 

On 29 September 2010 11:07, silky <[email protected]> wrote:

It affects everyone using .NET. 

 

Everyone using ASP.NET who uses session state/view state etc. If you don't
use these things then there is no impact for you.

 

Though this:
http://weblogs.asp.net/scottgu/archive/2010/09/18/important-asp-net-security
-vulnerability.aspx

 

says: 

What does the vulnerability enable?

 

An attacker using this vulnerability can request and download files within
an ASP.NET Application like the web.config file (which often contains
sensitive data).

 

At attacker exploiting this vulnerability can also decrypt data sent to the
client in an encrypted state (like ViewState data within a page).

 

Has anyone read any more specifics on that part?

 

David.

 

-- 
David Connors |  <mailto:[email protected]> [email protected] |
<http://www.codify.com> www.codify.com
Software Engineer
Codify Pty Ltd
Phone: +61 (7) 3210 6268 | Facsimile: +61 (7) 3210 6269 | Mobile: +61 417
189 363
V-Card:  <https://www.codify.com/cards/davidconnors>
https://www.codify.com/cards/davidconnors
Address Info:  <https://www.codify.com/contact>
https://www.codify.com/contact

Reply via email to