RedirectMode in ASP.NET Security Vulnerability

In a Scott Guthries blog post about ASP.NET security vulnerability noted here , he says that for ASP.NET 3.5 SP1 + there should be the following attribute in the user error section

redirectMode="ResponseRewrite"

What is the significance of this in relation to vulnerability and why only 3.5 SP1 and higher?

+3
source share
2 answers

ResponseRedirect provides the attacker with information about the time it takes to get the redirect header.

ResponseRewrite did not return the redirect header, so the attacker did not know this time.

, , , error.aspx . ResponceRewrite, .

3.5 SP1 , .s

+1

3.5 SP1 ? .

. (ResponseRedirect) . ResponseRewrite - Uri. , , .

MSDN ...

0

Source: https://habr.com/ru/post/1765638/


All Articles