Do not use Public ASP.NET keys (DUH), Microsoft warns

Microsoft Sondera Intelligence in December Uses “Interpretering character” that uses the Support Video Khoz.net. The company pointed to more than 3,000 of the USP.NET machine keys – IE, keys displayed in the code text and repositories – which can be used in the Viewstate code forms.

In response, Microsoft Innation Intelligence is a warning organizers to copy keys from publicly and invigorating the keys. In the Bulletin, Microsoft Sondera is on the Interance and the protection of this work, has seen an unpredictable practice of the USP.NET machine, and other public sources used by threatening actors to perform malicious servants. . While many other previously known times of the Embed or stolen Code used in the black web site, these products are publicly dangerous because they are found in the development code without conversion code, and Microsoft said. The worst danger of Microsoft Sondera Intellion continues to look at the additional use of this attack, Microsoft said.

ViewState is a method of ASP.net web savings for the preservation of forms and controls between Postbacks characters, means Microsoft Sounderance an Intelligence. ViewState data is kept in a hidden field on the page and installed. Protecting disorders and disclosure, the outline of the port.net page uses mechanical keys. “If those keys are stolen or made available to threatening players, these threatening players can make bad creativity using the shared buttons. “When the application is processed by the targeted ViewState in the targeted server, Viewstate is postponed and confirmed as the applicable buttons. of the net. “


Source link