ASP.Net 1.1 Viewstate Security -
In ASP.Net 1.1, it is possible that the end user should be sent back to the server before converting it, for example It seems that an item has been selected in the dropdown that does not exist? I have tried to manipulate the values in the dropdown using the firebug but the server ignored it, because I think Victwette says that the item does not exist, if it is possible, to achieve it It is possible to change the data, so it can be more of a problem.
I am asking because I have been asked to consider the security of one of our applications and if possible, then there may be a major security flaw
Just to clarify I am not saying that, I do not want to break any other software, I need to know that something is worried about it.
Hope this makes sense.
Thanks
Yes, see the state can be hacked. A feature was introduced in ASP.NET 2.0, which prevented and prevented such attacks.
Description How to hack the scene status of an application.
Comments
Post a Comment