Why sleep is good for your app’s padding oracle health(www.troyhunt.com)

submitted by troyhunttroyhunt(831) 1 year, 7 months ago

Does the ASP.NET padding oracle vulnerability benefit from random sleep periods in the error page as Microsoft claims? Is it possible to execute a timing attack against apps that don’t have this? Are earlier versions of ASP.NET more vulnerable to the whole padding oracle vulnerability? Yes, yes and yes!

add a comment |category: |Views: 81

tags: another

new Add a live kick counter to your blog >> liveImage

You can even customize the image by choosing your own colors, and then clicking the button below to update the preview and the html code:

  • "Kick It" text
  • "Kick It" background
  • kick count text
  • kick count background
  • border

Simply copy and paste this HTML into your blog post.


Users who kicked this story:
Comments:

No comments so far

information Login or create an account to comment on this story