POET vs ASP.NET: DotNetNuke
Sign in to YouTube
Sign in to YouTube
Sign in to YouTube
Uploaded on Sep 16, 2010
In this video we show how to use POET to attack the latest version of ASP.NET. The target application is DotNetNuke. The attack consists of two phases:
1. In the first phase, we use POET to extract DotNetNuke's secret keys, and use those keys to generate a cookie to login as a super user. The same technique can be used to attack _every_ ASP.NET application.
2. In the second phase, we use Cesar Cerrudo's Token Kidnapping attack to gain SYSTEM privilege on the Windows server hosting DotNetNuke.
This research was done by Thai Duong and Juliano Rizzo. More information can be found at http://netifera.com/research.
-
Category
-
License
Standard YouTube License
- Buy "Hey There Delilah" on
Google PlayeMusicAmazonMP3iTunes -
Artist
Plain White T's
Loading...
Loading...
Loading...
Loading...
-
1:37
Padding Oracle Exploit Tool vs Apache MyFacesby netiferaFeatured
28,691
-
5:01
Details and exploit code for .NET Padding Oracle attackby xcd3
12,860 views
-
3:46
Exploiting the ASP.NET vulnerability in 565 requestby ImmunityInc
4,846 views
-
4:44
Cracking CAPTCHA with Padding Oracle attackby cryptbe
17,161 views
-
1:44
Как работают профи веб-разработкиby nikitaudaltsov
339,938 views
-
3:13
Dot Net Vs JAVA.flvby amangupta0051
13,843 views
-
ASP.NET
10,791 videos550
-
2:10
ASP Admin Hacked. SQL Injectionby lobstaish
48,995 views
-
4:47
ASP.NET MVC Model view controller ( MVC) Step by Step Part 1by dnfvideo
148,805 views
-
58
videos
Play all
ASP.NETby zultek85
-
9:16
DotNetNuke Module Development Template Installationby dotnetnuke
7,287 views
-
10:15
ASP.NET Tutorial Part2by learningdom
86,315 views
-
7:15
DotNetNuke 6.2 Getting Startedby dotnetnuke
16,721 views
-
2:09
POET vs ASP.NET: don't waste time implementing useless workarounds - you should patch ;-)by cryptbe
4,117 views
-
7:56
An Introduction To DotNetNukeby Bill Stevens
18,489 views
-
1:36
Why DotNetNuke?by applydnn
7,702 views
-
9:56
Create a Login Form in ASP.Net (for more Cooltuts.com)by Emmu Mendu
53,394 views
-
6:52
DotNetNuke Professional Edition 5.1 Content Approvalby DNNOnline
8,886 views
-
12:08
Content Management System (CMS) - ASP.Net, MS SQL - DotNetNuke DNN - Overview - Part 1 of 2by Chris Reddick
4,896 views
-
4:02
Word Press VS DotNetNuke - A funny cartoonby datasprings
2,439 views
-
13:41
SQLi And Defeacment + Shell Upload Part 2by ig881997
1,850 views
-
10:00
Three Tier Data Access using ASP.NET 2.0 Part 1 of 6by BlackBearIT
45,735 views
- Loading more suggestions...
Uploader Comments (cryptbe)
cryptbe 2 years ago
@Drysar0: ha! thanks for pointing out. We made a mistake because we are new to ASP.NET, and we wanted to demonstrate that error message is irrelevant, so we skimmed the documentation and thought that setting CustomErrors="Off" is the most secure.
What we can say is the setting of CustomErrors is _irrelevant_. We presented this at EKOPARTY, and we're going to release the slide deck soon.
Sign in to YouTube
Sign in to YouTube
Top Comments
fukutabe 2 years ago
Downvoted for douchey music.
Sign in to YouTube
Sign in to YouTube
All Comments (72)
thomas hondema 5 months ago
Do you still have the poet.py script?
Sign in to YouTube
Sign in to YouTube
oddstrat 10 months ago
I need the this poet.py script to test my asp.net app, urgently..
please help me..
i have googling a week but still not got it :(
Thanks before
Sign in to YouTube
Sign in to YouTube
Natnael Lulie 1 year ago
Please i have a problem in running poet.py in python script.it says insufficient argument.pls help!
Sign in to YouTube
Sign in to YouTube
tiagobevilaqua 1 year ago
My Listening is not good enough for that. But it took using the Shazam! - "Plain White Ts - Hey There Delilah".
Sign in to YouTube
Sign in to YouTube
tiagobevilaqua 1 year ago
My Listening is not good enough for that. But it took using the Shazam! - "Plain White Ts - Hey There Delilah".
Sign in to YouTube
Sign in to YouTube
tiagobevilaqua 1 year ago
My Listening is not good enough for that. But it took using the Shazam! - "Plain White Ts - Hey There Delilah".
Sign in to YouTube
Sign in to YouTube
joertjoert 1 year ago
Google for the lyrics. "just believe me girl sometime I'll pay the bills with this guitar" should do the trick.
Sign in to YouTube
Sign in to YouTube
Larry Viezel 2 years ago
So - assuming you have CustomErrors not set to "Off" and and redirectmode set to "ResponseRewrite" - does this protect you from this vulnerability? Or is this irrelevant?
Sign in to YouTube
Sign in to YouTube