Rank: Advanced Member Groups: Member
Joined: 8/13/2006 Posts: 41 Points: 81
|
A major security flaw in ASP.NET was announced on Friday — one that affects all versions and can allow an attacker to see ViewState and web.config data in clear text. As such, everyone who has made an ASP.NET Web site should take this threat very seriously. Microsoft is putting together a patch. Until then, they suggest a workaround of turning on customErrors, and having it point to a single error file. http://www.dougv.com/blog/2010/09/18/major-security-hole-in-asp-net-requires-error-redirect-workaround/
|
Rank: Administration Groups: Administration
, Member
Joined: 12/30/2004 Posts: 1,674 Points: 1,824 Location: Wageningen (NL)
|
Thanks! I've made it a sticky until a more permanent fix is issued by Microsoft.
|