Quantcast
Viewing latest article 12
Browse Latest Browse All 21

Danger of Stealing Auto Generated .NET Machine Keys

In the Exploiting Deserialisation in ASP.NET via ViewState blog post, I explained how it is possible to run code on an ASP.NET web application using compromised Machine Key secrets. It covers cases in which the keys are hard coded and could be read using another vulnerability such as local file disclosure. However, most websites do […]

Viewing latest article 12
Browse Latest Browse All 21

Trending Articles