Web Hack List

Collected research

Source Code Disclosure in ASP.NET apps

Reports that ASP.NET cookieless session tokens embedded inside a URL path let a request reach files IIS otherwise refuses, because the token is stripped after request filtering has run. On servers configured with runAllManagedModulesForAllRequests, inserting the token inside a path segment retrieves compiled assemblies from the application's bin directory, disclosing source code and, in the case studied, an exploitable flaw. Short-name enumeration recovers the file names needed.

Record

Researcher
Arseniy Sharoglazov and @_mohemiv
Published by
PT SWARM
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Arseniy Sharoglazov and @_mohemiv, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .