« Hidden Linux : Sensing temperature | Main | Time to biff your HD telly? »


If you're in charge of an ASP.NET server, you might have some overtime coming. Quite a lot of it.

A pair of security researchers have implemented an attack that exploits the way that ASP.NET Web applications handle encrypted session cookies, a weakness that could enable an attacker to hijack users' online banking sessions and cause other severe problems in vulnerable applications. Experts say that the bug ... affects millions of Web applications.
(Emphasis added)


You'll find a lot more detail in the link above, but this rather tuneful clip gives you an idea of the essence -- and simplicity -- of the attack ...


Stealing the keys to create a super-user's cookie takes less than 5 minutes. From then your server's pwned!

The list of affected systems is impressive: Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2. Microsoft's response has so far been measured, though they do note that "Microsoft is aware of limited, active attacks at this time."

I hope they're not against my bank. Or yours!


Follow Geoff Palmer on Twitter

Comments

Actually after looking into it, it could be a lot worse not going to be a big deal for most sites I think you'll find.

I'm glad most of our projects are OSS based but we have one small asp project so will have to check it ouch!

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

Subscribe
Newsletter & SubscriptionsPC World is New Zealand’s top selling computing and technology magazine.

It provides up-to-the-minute editorial, insight and buying advice for personal computing, cell phones, game consoles, digital entertainment and broadband.
SIGN UP
PCWorldUpdate
PC World's weekly round-up of tech news, gear and game reviews, software selections, and handy How Tos.