Reading into it, it is not enough to just have CustomErrors on to mitigate the risk. There are some pretty detailed instructions, involving pushing all errors to a single page, with a random delay embedded in the page script.
They seem intentionally vague about how someone can use this to get asp.net to dump the web.config however.
Comments
Reading into it, it is not enough to just have CustomErrors on to mitigate the risk. There are some pretty detailed instructions, involving pushing all errors to a single page, with a random delay embedded in the page script.
They seem intentionally vague about how someone can use this to get asp.net to dump the web.config however.