Microsoft warns of .Net vulnerability
Microsoft offers workaround and prepares patch after researchers reveal hole in ASP.Net software used in millions of Web sites.
Microsoft is warning people of a potentially serious vulnerability in its ASP.Net framework used to create Web sites.
"At this time we are not aware of any attacks using this vulnerability and we encourage customers to review the advisory for mitigations and workarounds," the company said in a blog post.
Microsoft also provided a script to help administrators determine if their ASP.Net applications are vulnerable.
The vulnerability is caused by ASP.Net providing Web clients details in error messages when decrypting certain ciphertext, Microsoft said. An attacker could be able to read or tamper with data that was encrypted by the server, as well as read data from files on the target server.
Microsoft's security advisory came after two researchers presented a talk on the vulnerability at the Ekoparty security conference in Buenos Aires on Friday.
"You can decrypt cookies, view states, form authentication tickets, membership password, user data, and anything else encrypted using the framework's API!" the researchers said in the description of their talk on the conference Web site. "The vulnerabilities exploited affect the framework used by 25 percent of the Internet websites. The impact of the attack depends on the applications installed on the server, from information disclosure to total system compromise."