Home
Resources
Training
About Us
eStore
<a href="http://www.isdecisions.com/en/software/userlock/?xtor=SEC-230"><img src="http://www.isdecisions.com/images/pubs/Randy/userlock.gif" alt="UserLock" border="0" /></a>

>

resources > bulletins > MS06-033

 

 

 

 

 

 

 

Latest Blog: WinReporter 4.0 Makes It Easy to Assess Attack Surface

 

Microsoft Security Bulletin MS06-033 - Vulnerability in ASP.NET Could Allow Information Disclosure (917283)

This vulnerability in ASP.NET 2.0 web applications allows an attacker to access by bypass ASP.NET security and request files from application folders if the attacker knows the specific name of the file.  If successful this would like provide the attacker with sensitive information about the application’s inner workings which the attacker to could leverage in further attacks on the application.  Application folders are named “App_*”.   The mitigating factors and viable workarounds published in this bulletin will allow most of you to defer installation of this update until you can fully test it with your applications.

Get this valuable commentary each month as soon as Microsoft releases security updates!

Free log parser scripts, a clear explanation of Microsoft's latest security bulletin, helpful security tips, how-to's and more.

Email address:

 

Newsletter archive
Your e-mail address will be held strictly confidential and you can unsubscribe at any time.


Upcoming Webinars by Randy Franklin Smith


Additional Links

A
D
V