Critical .NET vulnerability patched !Best Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
Internet security & monitoring for networks - Dld trial!   Get A Free iPod   Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
2009/12/24 0:00:00
2009/11/20 17:37:24
2009/11/20 17:37:24
2009/11/20 15:43:34
2009/11/20 15:43:34
Our Partners
Downloads
Web Security : Critical .NET vulnerability patched !
Posted by Max on 2007/7/20 8:00:00 (1004 reads)
Web Security

Steps have finally been taken by Microsoft to protect millions of exposed networks vulnerable to a .Net exploit that was first discovered nine months ago.During that time many customers were not only left in the dark, but left dangerously exposed by the vulnerability which was a null byte exploit.

The company has tried to patch the exploit since its discovery by analyst group Security-Assessment.com last October, and has kept mum on the flaw which was uncovered in the US this week as a result of Patch Tuesday.

Security consultant and researcher at Security-Assessment.com Matthew Strahan said a filename which contains a null byte in the .Net environment can launch a Null byte injection attack which allows servers to be fully compromised.

He said a flaw exists in an upload file code when the .Net Common Language Runtime (CLR) considers Null bytes as data to directly call a native C function call.

"The flaw could be very dangerous when affected servers are trying to receive uploaded files; a null byte will terminate strings in lower level layers but won't for strings in higher level layers," Strahan said.

"The attack means you can upload any code you want to take over the entire server.

"If you upload a .aspx file, followed by a Null byte and an extension such as .txt, it will be saved as a txt file. [Native function] calls at the injected Null byte allows a remote user to terminate a sting parameter which can lead to a compromise."

.Net vulnerability bytes Web servers




Other articles
2009/11/3 14:55:39 - BitDefender Top Ten Malware Threats for October 09
2009/11/3 14:29:38 - Nov. 09 Microsoft Security Intelligence Report
2009/10/7 15:19:17 - StopSign AntiVirus and Anti-Malware is Windows 7 Compatible
2009/10/7 15:11:26 - New Outlook Backup and Migration Software By Disk Doctors
2009/9/30 4:20:57 - Microsoft Security Essentials, FREE Security Tool Just Released
2009/9/28 14:31:52 - New Rogue Antispyware Cloaked To Infects Computers
2009/9/9 4:31:49 - Trend Micro Proves Leadership in URL Filtering and Web Security
2009/9/9 4:16:20 - New Free Tool to Clean Conficker Once and For All
2009/9/1 8:37:11 - Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010 Out Now
2009/9/1 7:54:50 - NEW P2P Advertising Network Protects Users Against Lawsuits And Identity Theft

The comments are owned by the poster. We aren't responsible for their content.