Blog Post RSS ?

Blogs » .NET » ASP.NET Security Threat
 

ASP.NET Security Threat

by miseldine

I’ve been busy fixing the many applications at University today with this new security threat to ASP.NET applications.

Put simply, its a matter of canonicalization that could allow users to enter password protected areas of your sites by simply altering a URL.

A good how-to guide is available on the Microsoft support site, yet no formal fix has yet been released. You can protect your application however, by dropping 5 lines of code into your global.asax (available on the page)

Also for .NET developers, grab the patch for the GDI+ JPEG buffer overrun bug that has also recently been fixed.

Update: You can now download a patch to update your servers. Thanks to tchansen for the heads up.

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • Ping.fm
  • Twitthis

Related posts:

  1. Security Tip: Update Your Flash Player Adobe applications come under more fire with alerts of serious...
  2. Bad News for Microsoft: Windows, IE Net Usage Dip Lower According to Net Applications, share of web visits for Microsoft...
  3. Microsoft Security Essentials: a Review Microsoft Security Essentials may be free but is it any...
  4. Webmail Security Breaches Continue Hackers and criminals are exploiting the accounts of the 30,000...
  5. Australia’s Net Censorship Sparks Outrage Australia's government is about to launch a mandatory nationwide censoring...

This post has 4 responses so far

Sponsored Links

SitePoint Marketplace

Buy and sell Websites, templates, domain names, hosting, graphics and more.

Follow SitePoint on...