POET vs ASP.NET: DotNetNuke

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
71,129
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Sep 16, 2010

In this video we show how to use POET to attack the latest version of ASP.NET. The target application is DotNetNuke. The attack consists of two phases:

1. In the first phase, we use POET to extract DotNetNuke's secret keys, and use those keys to generate a cookie to login as a super user. The same technique can be used to attack _every_ ASP.NET application.

2. In the second phase, we use Cesar Cerrudo's Token Kidnapping attack to gain SYSTEM privilege on the Windows server hosting DotNetNuke.

This research was done by Thai Duong and Juliano Rizzo. More information can be found at http://netifera.com/research.

Category:

Science & Technology

Tags:

License:

Standard YouTube License

Link to this comment:

Share to:

Uploader Comments (cryptbe)

  • @Drysar0: ha! thanks for pointing out. We made a mistake because we are new to ASP.NET, and we wanted to demonstrate that error message is irrelevant, so we skimmed the documentation and thought that setting CustomErrors="Off" is the most secure.

    What we can say is the setting of CustomErrors is _irrelevant_. We presented this at EKOPARTY, and we're going to release the slide deck soon.

Top Comments

  • Downvoted for douchey music.

see all

All Comments (70)

Sign In or Sign Up now to post a comment!
  • Please i have a problem in running poet.py in python script.it says insufficient argument.pls help!

  • @joertjoert My Listening is not good enough for that. But it took using the Shazam! - "Plain White Ts - Hey There Delilah".

  • @joertjoert My Listening is not good enough for that. But it took using the Shazam! - "Plain White Ts - Hey There Delilah".

  • @joertjoert My Listening is not good enough for that. But it took using the Shazam! - "Plain White Ts - Hey There Delilah".

  • @tiagobevilaqua Google for the lyrics. "just believe me girl sometime I'll pay the bills with this guitar" should do the trick.

  • So - assuming you have CustomErrors not set to "Off" and and redirectmode set to "ResponseRewrite" - does this protect you from this vulnerability? Or is this irrelevant?

  • NameError: global name 'reduce' is not defined

  • I have the following error when write this function in pyton

    Traceback (most recent call last):

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more