Skip to content

Comment on New ASP.NET Security Vulnerability could allow access to web.configparent

Comments

The article is a bit vague there, bit I didn't read it to mean you couldn't distinguish 404s from 500s.

It seems to say that you shouldn't tell people which flavor of 5xx he got, since that's useful info to an attacker.

As I mentioned in another thread, this doesn't seem like it would affect any real sites, so it's not a case of waiting for (gasp) months for a patch while your server is in real jeopardy.

Security warnings like this come through for ASP.NET a couple times a year, but nearly all of them are of the "don't do the stuff you already shouldn't be doing, or bad things might happen" variety.

The 404 restriction is driven home in the comments. Many users ask and its repeated several times that all errors should be 500, even 404.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.