Microsoft is warning people of a potentially serious vulnerability in its ASP.NET framework used to create Web sites.
The hole affects all versions of the .NET framework and affects Windows XP, Vista, Windows 7, and Windows Server 2003 and 2008, company said in an advisory released late on Friday.
"At this time we are not aware of any attacks using this vulnerability and we encourage customers to review the advisory for mitigations and workarounds," the company said in a blog post.
Microsoft also provided a script to help administrators determine if their ASP.NET applications are vulnerable.
The vulnerability is caused by ASP.NET providing Web clients details in error messages when decrypting certain ciphertext, Microsoft said. An attacker could be able to read or tamper with data that was encrypted by the server, as well as read data from files on the target server.
Microsoft's security advisory came after two researchers presented a talk on the vulnerability at the Ekoparty security conference in Buenos Aires on Friday.
"You can decrypt cookies, view states, form authentication tickets, membership password, user data, and anything else encrypted using the framework's API!" the researchers said in the description of their talk on the conference Web site. "The vulnerabilities exploited affect the framework used by 25 percent of the Internet websites. The impact of the attack depends on the applications installed on the server, from information disclosure to total system compromise."
Search This Blog
Followers
Blog Archive
-
▼
2010
(120)
-
▼
September
(32)
- Everest software
- prevent you pc being hacked
- Htc qwerty android phone
- google Tv the future of tv
- Symbian 3 review
- Twitter hacked.
- Mafia 2
- LG 31 inch Oled TV
- .net frame vulnerable says microsoft
- Invite 15 on facebook and 21000 reoly
- acer aspire revo
- New ARM processors 2+ GHz on your phone
- stay on gtalk on mobile
- Lenovo s10-3t.
- use Usb thumb drive with nokia phones
- New nokia E7
- tweet from your mobile
- Philips GoGear Spark
- some things better than the iPad
- sony walkman a845
- acer TimelineX4820TG
- best ebook reader Kindle vs Nook vs iPad
- New iPods and social iTunes
- Texas opens antitrust investigation of Google
- Samsung galaxy tab
- Best Drive-way in the world.
- India wants local servers from RIM, Google, Skype
- Toshiba Laptops overheating., recalls 41000 laptops
- Most internet scams are from Nigeria according to ...
- Cisco on smart-grid networking
- 3d coming soon to ps3
- Video post by red hooded girl.
-
▼
September
(32)
Monday, September 20, 2010
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment