ASP .NET Security Stuffed

Researchers have discovered bugs in the how ASP .NET implements it’s encryption protection for cookies. It’s bad.
“We knew ASP.NET was vulnerable to our attack several months ago, but we didn’t know how serious it is until a couple of weeks ago. It turns out that the vulnerability in ASP.NET is the most critical amongst other frameworks. In short, it totally destroys ASP.NET security,” said Thai Duong, who along with Juliano Rizzo, developed the attack against ASP.NET.
Read it here on threatpost
But hey, at least I get to use my security guard asleep on the job photo again!

Comments
Post new comment