Collected research
Deep understand ASPX file handling and some related attack vectors
Reverse-engineers how IIS compiles ASPX pages into cached DLLs under Temporary ASP.NET Files, including the code generation directory and the eight-character cache key algorithms. An attacker able to write there plants a backdoor DLL that hijacks a page without touching webroot, tampers across application pools that share one identity group, or reaches filtered URLs by cache key collision.
Record
- Researcher
- @rskvp93 and rskvp93
- Published by
- Blog of Viettel Cyber Security
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @rskvp93 and rskvp93, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .