lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Mon, 4 Oct 2010 10:21:08 +0200 From: Early Warning <seclist@...dedsecurity.com> To: full-disclosure@...ts.grok.org.uk Subject: Breaking .NET encryption with or without Padding Oracle Dear list, Since Microsoft official fix is out, we published full details about "ScriptResource.axd" vulnerability in framework 3.5 sp1 and above which leads to arbitrary file disclosure in the virtual path. In addition we have included also details about the "T" exploit that can be used to circumvent initial Microsoft workaround. For more information: http://blog.mindedsecurity.com/2010/10/breaking-net-encryption-with-or-without.html Regards, Giorgio Fedon Minded Security Research Team www.mindedsecurity.com _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists