Create an Account
username: password:
 
  MemeStreams Logo

Syscan - Next Generation .NET Vulnerabilities.pdf

search

Acidus
Picture of Acidus
My Blog
My Profile
My Audience
My Sources
Send Me a Message

sponsored links

Acidus's topics
Arts
Business
Games
Health and Wellness
Home and Garden
Miscellaneous
Current Events
Recreation
Local Information
Science
Society
Sports
Technology

support us

Get MemeStreams Stuff!


 
Syscan - Next Generation .NET Vulnerabilities.pdf
Topic: Miscellaneous 11:21 am EST, Nov 14, 2008

Pretty cool analysis. The "ASP.NET's ValidateRequest stops XSS so its up to the dev to mess it up" is incorrect. Ignore esoteric attacks like double/triple encodings, etc. Lets do something basic.

" onmouseover="alert('xss')

ValidateRequest does not stop attribute injection attacks.

Syscan - Next Generation .NET Vulnerabilities.pdf



 
 
Powered By Industrial Memetics
RSS2.0