Skip to content

Comment on Security researchers 'destroy' Microsoft ASP.NET securityparent

Comments

Check out the quote that the authors of the paper in question note:

The most significant new discovery is an universal Padding Oracle affecting every ASP.NET web application. In short, you can decrypt cookies, view states, form authentication tickets, membership password, user data, and anything else encrypted using the framework's API!

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.