Penetration Testing mailing list archives

Re: Pen-tester's analysis of .NET security?


From: Frank Knobbe <frank () knobbe us>
Date: Wed, 24 Mar 2004 17:24:12 -0600

Sorry, gotta correct myself.

Can't help with white papers, but while doing reviews of sites "powered
by ASP.NET" I noticed that these mostly use ADODB connections which *MAY*
escape quotes. 

The web app I'm looking at currently was not vulnerable to quotes. But I
just came across additional quote escaping before the command string
hits the ADODB.Command object. Perhaps ADODB is still vulnerable.

In either case, never trust the OS. :)

-Frank


Attachment: signature.asc
Description: This is a digitally signed message part


Current thread: