Massive BlogEngine.Net Security Hole - Fix Provided(dannydouglass.com)

submitted by TroyMGTroyMG(2670) 3 years, 9 months ago

A massive security hole in BlogEngine.net was just revealed that allows anyone to see your passwords... Danny Douglass explains the issue and provides a patched BlogEngine.Core assembly to resolve the issue until the next release of BlogEngine is available.

4 comments |category: |Views: 62

tags: another

new Add a live kick counter to your blog >> liveImage

You can even customize the image by choosing your own colors, and then clicking the button below to update the preview and the html code:

  • "Kick It" text
  • "Kick It" background
  • kick count text
  • kick count background
  • border

Simply copy and paste this HTML into your blog post.


Users who kicked this story:
Comments:

posted by rimsystemsrimsystems(6119) 3 years, 9 months ago 0

This needs to get fast-tracked to the home page!

Reply

posted by aquinasaquinas(20) 3 years, 9 months ago 0

Why is the password stored in plain text?

Reply

posted by TroyMGTroyMG(2670) 3 years, 9 months ago 0

Good question...

Reply

posted by yesthatmcgurkyesthatmcgurk(4063) 3 years, 9 months ago 0

Mads needs to read this article: http://statestreetgang.net/post/2008/04/A-NET-Cryptography-Primer2c-Part-Two.aspx

Reply

information Login or create an account to comment on this story