[VulnDiscuss] Re: Security issues with Asp.Net in Shared Hosting Environments

Dave Aitel <[email protected]> 30 Oct 2003 15:20:16 -0600
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Organization Immunity, Inc.
Message-ID <[email protected]>
I'm confused about the following issue:

On Thu, 2003-10-30 at 12:03, Dinis Cruz wrote:
> Hello 

> c) "Asp.Net.Vulnerability: Asp.Net buffer overflows (potential security
> problems)"
> (http://www.asp.net/Forums/ShowPost.aspx?tabindex=1&PostID=369016) 

>From what I can tell, you are worried that someone will use the Win32
API calls to exploit a box they are hosted on. Now, I'm no .Net
programmer, but I assume that they can, using only .Net, call
Net.Socket.Connect() and Net.Socket.Send() or something similar to that,
in addition to using raw Win32 calls. Using these, they can easily
attack the local machine by formating their own RPC requests manually.

Is your concern better worded "Asp.Net Vulnerability: ASP.Net hosted on
insecure Windows-based platform?"

Dave Aitel
Immunity, Inc.