Error!
Success!

Vulnerability in .NET AES puts ASP.NET Web Sites at Risk

0
kicks

Vulnerability in .NET AES puts ASP.NET Web Sites at Risk  (Unpublished)

ASP.NET web applications that leverage Forms Authentication, ASP.NET Membership Providers, ASP.NET Role Providers, and/or ViewState encryption are vulnerable to data exposure and potentially tampering. This vulnerability can lead to the .NET MachineKey being discovered by attackers. This post briefly details the issue and provides a simple temporary mitigation technique.


Kicked By:
Drop Kicked By: