WHIR | BLOGS | WEB HOST NEWS | FIND WEB HOSTS | RESELLER HOSTING | MAGAZINE | WHIR TV | NEWSLETTER | rss feeds
web hosting news - daily web host interviews, insight Jobs | Events | Sitemap | Search
Green Data Center Info


WEB HOSTING NEWS | BLOGS | INTERVIEWS | EUROPE | EVENTS | WEB HOSTING JOBS

<< Authorities Seize Rackspace Servers     MCNC Opens Data Center to Start-Ups >>


ASP.NET Flaw Could Allow Intrusions

October 7, 2004 -- (WEB HOST INDUSTRY REVIEW) -- According to research and analysis firm Netcraft (netcraft.com), a security flaw in Microsoft?s ASP.NET technology potentially allows intruders to enter password-protected areas of a Web site by altering the URL.

   
DataPipe’s high-value managed global IT services help thousands of businesses decrease CAPEX, OPEX, & risk while increasing overall service levels. Partner with DataPipe – Improve your ROI - Extend your IT resources

Affects all versions of ASP.NET on Windows 2000, Windows 2000 Server, Windows XP Professional and Windows Server 2003, the flaw involves ASP.NET's handling of URLs, known as "canonicalization." If a visitor to an ASP.NET site substitutes '\' or '%5C' for the '/' character in the URL, they could bypass password login screens. The technique may also work if a space is substituted for the slash.

Netcraft said the flaw operates differently in Internet Explorer and Mozilla browsers.

A patch for the flaw, the report said, is not yet available, but Microsoft has published guidelines to help ASP.NET users secure their Web sites from intrusion.

According to Netcraft data, over 2.9 million active sites run ASP.NET, a number that has been steadily climbing over the last year.

Print this Page       Email this Page        Add to: | del.icio.us | digg


COMMENTS

Be the first one to comment on this article. Click the link below to post your comment.

[POST COMMENT]



Q&A: Jim Lewandowski, Rackspace

Q&A: Clint Poole, Brinkster

New Features in Parallels Plesk 9

Q&A: James Bond, Apptix

Noise Filter: McColo Taken Down

Wowza Offers Friction Free Flash

Sun Battles for Greenest Data Center

More feature interviews and reports
 

What's the Deal with Cyber Monday?

Go Daddy Ads in the Grey Cup

Video Interview with Vinay Nagpal, Tata Communications

Copywriting for Direct Mail - Part 2: Big Guns

What Exactly is Semi-Dedicated Hosting?

Own your own jet

More posts from our Bloggers


The Planet Offers Unmetered Bandwidth

LINX Connects 300th Member

Dell Unveils Green Reno Services

HP Trims IT Infrastructure, Saves $1B

Logicworks Among Best NY Workplaces

Websense to Host Partner Conference

NameCheap Launches Twitter Promo

CBS Web Site Faces Malware Hack

VineyardHosting Limits Eternal Hosting

Email Use Increases As Economy Slows

HostNine Re-Launches New Website

SoftLayer Sponsors MSDN Conference


 

Marketing/Sales Trainer

Sales Operator

Management Trainer

Senior Account Manager, Dedicated Hosting

Sales Executive

Senior Accounting Analyst

Technical Solutions Engineer

Product Manager

Account Manager

Ajax Experienced Developer

 

SPONSORED LINKS
> Apollo Hosting: Award Winning Website Hosting from $6.96 – Click Here!

> iWeb: Quality servers. 3000GB of traffic for only $69

> TopLayer: SC Mag Recommended. Protect against DDoS Attacks & more.

> Parallels: Automation and Virtualization. Buy ONLINE or Learn MORE!

> Rackspace: What Do You Get With Your Hosting Provider?

> Verio: Get Email Anywhere w/ Hosted Exchange $11.95/mo, 2 Mo Free

> IronScale: Why Rack? Automate with IronScale Managed Hosting

> Learn more about the greening of the data center here.

> Is your company hiring? Post your job listing here!

> Get your company listed in our annual Buyer's Guide magazine issue - Deadline: Dec 31

WHIR NEWSLETTER SIGN-UP | MANAGE SUBSCRIPTIONS | WHIR RSS FEEDS
Name:
Email:
Password:
theWHIR Blog Email Update
Magazine
Daily News
Find Web Hosts
Occupation:
Company Type:

Find Web Hosts | Reseller Hosting | Personal Web Hosting | Small Business Web Hosting | Dedicated Servers | Managed Hosting | Adult Web Hosting


About WHIR | Online Advertising | Print Advertising | Print Subscription | Email Newsletters | RSS Feeds
 
Submit News | Privacy Policy | Buy Reprints

Web Host Industry Review, Inc. is not responsible for the content of comments submitted by our users.

  © Copyright Web Host Industry Review, Inc.