Quantcast
Channel: Soroush Dalili (@irsdl) Blog
Viewing all articles
Browse latest Browse all 21

Danger of Stealing Auto Generated .NET Machine Keys

$
0
0
In the Exploiting Deserialisation in ASP.NET via ViewState blog post, I explained how it is possible to run code on an ASP.NET web application using compromised Machine Key secrets. It covers cases in which the keys are hard coded and could be read using another vulnerability such as local file disclosure. However, most websites do […]

Viewing all articles
Browse latest Browse all 21

Trending Articles