ASP.Net 1.1 Viewstate Security -


In ASP.Net 1.1, it is possible that the end user should be sent back to the server before converting it, for example It seems that an item has been selected in the dropdown that does not exist? I have tried to manipulate the values ​​in the dropdown using the firebug but the server ignored it, because I think Victwette says that the item does not exist, if it is possible, to achieve it It is possible to change the data, so it can be more of a problem.

I am asking because I have been asked to consider the security of one of our applications and if possible, then there may be a major security flaw

Just to clarify I am not saying that, I do not want to break any other software, I need to know that something is worried about it.

Hope this makes sense.

Thanks

Yes, see the state can be hacked. A feature was introduced in ASP.NET 2.0, which prevented and prevented such attacks.

Description How to hack the scene status of an application.


Comments

Popular posts from this blog

c++ - Linux and clipboard -

What is expire header and how to achive them in ASP.NET and PHP? -

sql server - How can I determine which of my SQL 2005 statistics are unused? -