• Login
  • Register
  • Login Register
    Login
    Username:
    Password:
  • Home
  • Members
  • Team
  • Help
User Links
  • Login
  • Register
  • Login Register
    Login
    Username:
    Password:

    Quick Links Home Members Team Help
    Tendo City Tendo City: Metropolitan District Ramble City Thinking outside the box (The dangers of .NET)

     
    • 0 Vote(s) - 0 Average
    Thinking outside the box (The dangers of .NET)
    etoven
    Offline

    Site Owner Operator

    Posts: 2,049
    Threads: 586
    Joined: 01-04-2019
    #1
    17th June 2006, 6:44 PM
    I discovered something last night, Microsoft has really done it now. There is an inherent weakness in the http protocol that until now could not be exploited, I say until now because .NET 2.0 is here. I believe this design flaw in the http protocol is so astronomical that no computer will be safe from viral attack, and there will be no way to defend against it.

    I’m speaking of .Nets ability to override http requests. Let me explain.

    As a demonstration go to the following link:

    http://talk.tovennet.net/speek.ashx?text...0a%20test'

    You will notice 2 things horribly wrong with this link. First of all the type of file it is, the extension is .ashx yet media playing thinks it’s wav file, additionally you will notice the content of the file is a voice saying what’s in the query string in this case "this is a test", try substituting something else in the query string.

    So to recap windows was confused as to the type of file that was elected to open, and 2 the content of the file was overridden and dynamically generated, there is no file called speek.ashx on my web server the http request was routed threw an override handler.

    Now let’s say I created a virtual file called reallycoolimage.jpg, the temptation is not to worry about electing to open harmless jpgs, however I could override the handler and send you reallyhorriblevirus.msi, and here’s the kicker! You just elected to open it!

    This is an inherent defect in the http protocol that the client does not receive notification of overridden or dynamic http requests.

    Now I not trying to be a doom sayer but this could be the end of internet security as we know it, something must be done and I don’t know what!
    Reply
    Reply
    Private Hudson
    Offline

    Posting Freak

    Posts: 1,074
    Threads: 64
    Joined: 08-16-2001
    #2
    12th July 2006, 4:16 AM
    Oh man.

    You typed all that up, and no-one has even replied? Hell, I'm replying, but I honestly didn't even bother to even read your post. Perhaps you should stick to unintelligable one-liners. But I digress.

    Regardless, here's something to spice the thread up somewhat..

    [Image: kumada01.jpg]

    [Image: gibson.jpeg]

    [Image: marie%20claire%20-%20jennifer%20hawkins%203.jpg]

    [Image: stalin.jpg]

    [Image: pink_drumset.jpg]
    If i had a dollar for every time i ran out of hair in the middle of a spoon making contest id only eat your children with a side of slaw and THOSE ARENT PILLOWS!!
    Reply
    Reply
    Weltall
    Offline

    Administrator

    Posts: 5,822
    Threads: 321
    Joined: 05-03-2000
    #3
    12th July 2006, 4:53 AM
    I love you, Mark Woodbridge. :o
    YOU CANNOT HIDE FOREVER
    WE STAND AT THE DOOR
    Reply
    Reply
    « Next Oldest | Next Newest »

    Users browsing this thread: 1 Guest(s)



    • View a Printable Version
    • Subscribe to this thread
    Forum Jump:

    Toven Solutions

    Home · Members · Team · Help · Contact

    408 Chapman St. Salem, Viriginia

    +1 540 4276896

    etoven@gmail.com

    About the company Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua.

    Linear Mode
    Threaded Mode