FYI, details of how to get the web.config are below.

Hope everyone is patched by now.


---------- Forwarded message ----------
From: Early Warning <secl...@mindedsecurity.com>
Date: Mon, Oct 4, 2010 at 7:21 PM
Subject: [Full-disclosure] Breaking .NET encryption with or without
Padding Oracle
To: full-disclos...@lists.grok.org.uk


Dear list,

Since Microsoft official fix is out, we published full details about
"ScriptResource.axd" vulnerability in framework 3.5 sp1 and above
which leads to arbitrary file disclosure in the virtual path.
In addition we have included also details about the "T" exploit
that can be used to circumvent initial Microsoft workaround.

For more information:
http://blog.mindedsecurity.com/2010/10/breaking-net-encryption-with-or-without.html


Regards,

Giorgio Fedon

Minded Security Research Team
www.mindedsecurity.com

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



-- 
silky

http://dnoondt.wordpress.com/

"Every morning when I wake up, I experience an exquisite joy — the joy
of being this signature."

Reply via email to