[<prev] [next>] [day] [month] [year] [list]
Message-ID: <AANLkTimB8ZfhngU+rRjctR-UUOjYDFiP2VkNj5jcJxpX@mail.gmail.com>
Date: Mon, 4 Oct 2010 10:21:08 +0200
From: Early Warning <seclist@...dedsecurity.com>
To: full-disclosure@...ts.grok.org.uk
Subject: Breaking .NET encryption with or without Padding
Oracle
Dear list,
Since Microsoft official fix is out, we published full details about
"ScriptResource.axd" vulnerability in framework 3.5 sp1 and above
which leads to arbitrary file disclosure in the virtual path.
In addition we have included also details about the "T" exploit
that can be used to circumvent initial Microsoft workaround.
For more information:
http://blog.mindedsecurity.com/2010/10/breaking-net-encryption-with-or-without.html
Regards,
Giorgio Fedon
Minded Security Research Team
www.mindedsecurity.com
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists