[VulnDiscuss] Re: Security issues with Asp.Net in Shared Hosting Environments
Dave Aitel <[email protected]> 30 Oct 2003 15:20:16 -0600
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Organization | Immunity, Inc. |
| Message-ID | <[email protected]> |
I'm confused about the following issue: On Thu, 2003-10-30 at 12:03, Dinis Cruz wrote: > Hello > c) "Asp.Net.Vulnerability: Asp.Net buffer overflows (potential security > problems)" > (http://www.asp.net/Forums/ShowPost.aspx?tabindex=1&PostID=369016) >From what I can tell, you are worried that someone will use the Win32 API calls to exploit a box they are hosted on. Now, I'm no .Net programmer, but I assume that they can, using only .Net, call Net.Socket.Connect() and Net.Socket.Send() or something similar to that, in addition to using raw Win32 calls. Using these, they can easily attack the local machine by formating their own RPC requests manually. Is your concern better worded "Asp.Net Vulnerability: ASP.Net hosted on insecure Windows-based platform?" Dave Aitel Immunity, Inc.