Any opinions expressed here are my own and not necessarily those of my employer (I'm self-employed).

Sep 28, 2010

ASP.NET vulnerability gets fixed!

There has been quite some discussion (and speculation!) about the ASP.NET padding oracle vulnerability on various blogs around the Internet the last couple of days. After Microsoft published an advisory on it, the ASP.NET community has been following ScottGu's blog closely.

The issue has seen increasing attention. Yesterday the vulnerability was mentioned on Schneier's blog, where he provided a link to a Threat Post from Kaspersky where the guys behind the exploit were interviewed. The vulnerability and exploit tools were also discussed. The threat post was dated September 13, four days before Microsoft released the first security advisory on the issue. Since then, the amount of information on the vulnerability has only increased throughout the Internet. Now, there's so much information available from different sources that there's not much security through secrecy left.

In today's Kaspersky article on the vulnerability the authors of the exploit state that Microsoft's workarounds are ineffective. These guys seem very confident in the effectiveness of their attack. But as long as the attack relies on observing different behaviour occurring over a series of requests to a webserver, Microsoft's workarounds make sense. It's all about maximising the effort an attacker has to put into a successful attack — through reducing his likelihood of success per time period. In the demo, it took 38 000 web requests before the attack was successful. E.g. Doubling the amount of requests necessary for a successful attack will buy valuable time!

But, good news has arrived as I'm writing this! ScottGu just blogged about a security update shipping tomorrow! Honestly, we've been looking forward to this one! I guess a lot of people will spend the next day or two testing the patch. Happy patching! :)


  1. I think that you should definitely read this and learn something new. It was really useful for me in college.

  2. Thank you for sharing an interesting and very useful article. And let me share an article about health here I believe this is useful. Thank you :)

    Obat Polip Telinga Alami Tanpa Operasi
    Obat Penghancur Kista Ovarium
    Obat Nyeri Tumit Tradisional

  3. Gone off a Xany, nodding off, watching Menace. Rolling off some purple that my n-gga call Grimace read this.

  4. Thank you for this post. This is very interesting information for me.

  5. There are many vulnerabilities in Microsoft programs, and the most annoying thing is that most of these programs are paid. Therefore, it is better for students to choose software from other manufacturers; this does not guarantee 100% reliability, but at least it will save you money. Like the site CustomEssayMeister , where you can find the best tips on writing an essay.

  6. If you want to be like Einstein, you’ll find that it’s easier said than done. Not only did he have an amazing intellect, but he had a unique worldview that made it possible for him to think way outside the box. If you want to become a genius like Einstein, here’s how to start thinking like he did https://essaysprofessors.com/business-essay-writing-service.html .

  7. essay edge is a reliable online company that offers customers from all over the world professional help in writing academic papers. Its specialists are the best in exploring different subjects and creating great academic masterpieces.

  8. Thanks for this valuable information sharing, and i learned a lot and cleared my all doubts in this.. keep posting like this useful information.
    post free classified ads in india

  9. Hello everybody! Our essay writer net has been rated the best in completing diverse writing tasks given to students at their educational institutions, such as colleges, high schools, and universities. Our essay writer service has been crafting high-quality and flawless academic and custom pieces of writing for several years already.

  10. Thanks for this valuable information sharing, and i learned a lot and cleared my all doubts in this.. keep posting like this useful information.
    Scaffolding Dealers in Chennai
    Aluminium Scaffolding Dealers in Chennai

  11. Thanks for sharing this wonderful information. I hope you will share more helpful information regarding the content.
    web portal development company in chennai

  12. Thanks for sharing this wonderful information. I hope you will share more helpful information regarding the content.
    scaffolding dealers in chennai
    aluminium scaffolding dealers in chennai

  13. Hello, thanks for sharing this interesting information I appreciate reading. Moreover, the material mentioned here will be useful for a lot of people. Personally, I used in my care plan for constipation.

  14. ASP.NET is great tool for beginners who are interested in making websites. It is very easy to use. Just make database and start making your website. Best Assignment Writing

  15. Online project management writing services have become very popular among custom management writing service students seeking Management Coursework Writing Services and management essay writing services.


Copyright notice

© André N. Klingsheim and www.dotnetnoob.com, 2009-2018. Unauthorized use and/or duplication of this material without express and written permission from this blog’s author and/or owner is strictly prohibited. Excerpts and links may be used, provided that full and clear credit is given to André N. Klingsheim and www.dotnetnoob.com with appropriate and specific direction to the original content.

Read other popular posts