|
Παρουσίαση με Ετικέτες
Όλες οι Ετικέτε... » web » ASP.NET » Security (RSS)
-
Last week two security researchers, Thai Duong and Juliano Rizzo, have discovered a bug in the default encryption mechanism used to protect the cookies normally used to implement Forms Authentication in ASP.NET.
Using their tool (the Padding Oracle Exploit Tool or POET), they can repeatedly modify an ASP.NET Forms Authentication cookie encrypted ...
|
|
|