The Broadband Guide
SG
search advanced

Microsoft Issues Emergency Patch for Windows Web Bug

2010-09-29 03:15 by
Tags: , ,

 

As promised, Microsoft today delivered an emergency patch for a Windows Web server flaw that is being actively exploited by hackers.

The fix addresses a vulnerability in ASP.Net's encryption that attackers could abuse to access Web applications with full administrator rights; decrypt session cookies or other encrypted data on a remote server; and access and snatch files from sites or Web applications.

ASP.Net is the Microsoft-designed Web application framework used to craft millions of sites and applications.

Microsoft first sounded the alert Sept. 17 after a pair of researchers demonstrated how attackers could pilfer browser session cookies, or steal passwords and usernames from Web sites.

Three days later, Microsoft warned users that it was seeing limited, active attacks , and urged Web server administrators to apply the workarounds spelled out in an updated advisory.

Read more -here-

 

  Post your review/comments
    rate:
   avg:
News Glossary of Terms FAQs Polls Cool Links SpeedGuide Teams SG Premium Services SG Gear Store
Registry Tweaks Broadband Tools Downloads/Patches Broadband Hardware SG Ports Database Security Default Passwords User Stories
Broadband Routers Wireless Firewalls / VPNs Software Hardware User Reviews
Broadband Security Editorials General User Articles Quick Reference
Broadband Forums General Discussions
Advertising Awards Link to us Server Statistics Helping SG About