info
discussion
exploit
solution
references
Microsoft .NET Framework ASP.NET Padding Oracle Information Disclosure Vulnerability
References:
Another video may prove it all
(Thai Duong)
Automated Padding Oracle Attacks with PadBuster
(Brian Holyfield)
Breaking .NET encryption with or without Padding Oracle
(MINDED SECURITY RESEARCH LABS)
Investigating .NET Padding Oracle Exploitation with padBusterdotnet
(MINDED SECURITY RESEARCH LABS)
Microsoft .NET Framework Developer Center
(Microsoft)
Microsoft Homepage
(Microsoft)
Microsoft Security Bulletin Advance Notification for September 2010
(Microsoft)
MS ASP.NET padding oracle attack mitigation
(dragosr)
Out of Band Release to Address Microsoft Security Advisory 2416728
(Microsoft)
Practical Padding Oracle Attacks
(netifera)
Security Advisory 2416728 (Vulnerability in ASP.NET) and SharePoint
(Microsoft)
Security Advisory 2416728 - Workaround Update
(Microsoft Security Response Center)
Understanding the ASP.NET Vulnerability
(Microsoft)
Update to Security Advisory 2416728
(Microsoft)
ASA-2010-252: MS10-070 Vulnerability in ASP.NET Could Allow Information Disclosu
(Avaya)
Microsoft Security Advisory (2416728)
(Microsoft)
Microsoft Security Bulletin MS10-070
(Microsoft)
Privacy Statement
Copyright 2010, SecurityFocus