A few hours ago Microsoft posted a security advisory about a security vulnerability in ASP.NET.  This vulnerability exists in all versions of ASP.NET.

This vulnerability was announced and the tools to exploit the vulnerability were released late Friday at a “Security Conference”. 

For DotNetNuke users Cathal Connolly, our Security Specialist has posted a blog on how DotNetNuke users can mitigate against this potential attack.

The good news is – there are steps to mitigate the attacks. 

For more information:

Forms Authentication Vulnerability in ASP.NET – Shaun Walker – CoFounder and CTO, DotNetNuke Corporation

ASP.NET Security Vulnerability workaround for DotNetNuke sites – Cathal Connoly, Security Specialist, DotNetNuke Corporation

Important: ASP.NET Security Vulnerability - blog by Scott Guthrie, Corporate Vice-President, Microsoft Corporation

Microsoft Security Bulletin


Posted in: ASP.NET  Tags:

 Search Blog

 Calendar

«  September 2010  »
MoTuWeThFrSaSu
303112345
6789101112
13141516171819
20212223242526
27282930123
45678910
View posts in large calendar

 Tags

Disclaimer
The opinions expressed herein are my own personal opinions and do not represent my employer's view in anyway.

© Copyright 2012 Thoughts from the Wet Coast