MS11-100 exploit released
- https://threatpost.c...net-flaw-010912
Jan 9, 2012 - "A few days after MIcrosoft released a patch to fix a vulnerability in ASP.NET that could enable a denial-of-service attack, someone has released exploit code for the vulnerability. The proof-of-concept exploit code was posted to the Full Disclosure mailing list.. the code is designed to exploit a recently discovered vulnerability in ASP.NET that's related to the way that the software handles certain HTTP post requests... The problem isn't actually specific to ASP.NET, but affects a variety of languages and applications. Microsoft shipped an emergency patch* for the flaw on Dec. 29, recommending that users install it as quickly as possible... The base cause of the problem is that when ASP.NET comes across a form submission with some specific characteristics, it will need to perform a huge amount of computations that could consume all of the server's rresources."
* https://technet.micr...n/ms11-100.mspx
- https://isc.sans.edu...l?storyid=12355
Last Updated: 2012-01-09 19:21:27 UTC
Edited by AplusWebMaster, 10 January 2012 - 03:37 AM.