|
Scot Guthrie seems to be still bearing the weight of dealing with getting the news out about the on-going ASP .NET security problems. The latest update on his blog issues revised instructions on defending sites against the attack which basically include some additional measures.

In addition to the previous steps you should now also install and configure the IIS URLScan module (x86 Version or x64 Version).
Once URLScan is installed modify the UrlScan.ini file in this location:
%windir%\system32\inetsrv\urlscan\UrlScan.ini
Near the bottom of the UrlScan.ini file you’ll find a [DenyQueryStringSequences] section.
Add an additional “aspxerrorpath=” entry immediately below it and then save the file:
[DenyQueryStringSequences]
aspxerrorpath=
The above entry disallows URLs that have an “aspxerrorpath=” querystring attribute from making their way to ASP.NET applications, and will instead cause the web-server to return an HTTP error. Adding this rule prevents attackers from distinguishing between the different types of errors occurring on a server – which helps block attacks using this vulnerability.
After saving this change, run “iisreset” from a command prompt (elevated as admin) for the above changes to take effect. To verify the change has been made, try accessing a URL on your site/application that has a querystring with an aspxerrorpath and verify that an HTTP error is sent back from IIS.
Further reading
More on the ASP.NET vulnerability
New ASP .NET vulnerability
Microsoft Security Advisory 2416728 (Updated 9/24)
Understanding the ASP.NET Vulnerability
Initial Blog Post
Frequently Asked Questions Post
SharePoint Team Blog Post
Microsoft Security Response Center Blog Post
Microsoft Security Response Center Update Post
No Self Made Games For Xbox One 29/05/2013
Bits and pieces of information are appearing from Microsoft about the status of indie developers for the new Xbox One. It seems there is no place any more for anything but the big blockbuster games. I [ ... ]
|
Amethyst 2 - Visual IDE For Flex Developers 27/05/2013
Version 2 of SapphireSteel's Flash Platform IDE for Microsoft Visual Studio has been released providing visual design support for Flex, Flash and ActionScript developers.
| | More News |
|