Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
ASP.NET __VIEWSTATE crypto validation prone to replay attacks May 03 2005 01:38PM
Michal Zalewski (lcamtuf gmail com)
Good morning,

ASP.NET's extremely popular __VIEWSTATE functionality provides an automatic,
uniform method for storing current state of all webpage "controls" (including
form fields, database views, etc), so that user-entered data automagically
persists and is populated across newly rendered HTML...

[ more ]  





 

Privacy Statement
Copyright 2008, SecurityFocus