Skip to content

Comment on New ASP.NET Security Vulnerability could allow access to web.configparent

Comments

Reading into it, it is not enough to just have CustomErrors on to mitigate the risk. There are some pretty detailed instructions, involving pushing all errors to a single page, with a random delay embedded in the page script.

They seem intentionally vague about how someone can use this to get asp.net to dump the web.config however.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.