Wednesday, October 06, 2004 - Posts

MUST READ: What You Should Know About a Reported Vulnerability in Microsoft ASP.NET

For those of you working with ASP.NET, please be aware of the following reported security vulnerability in ASP.NET.

From Microsoft's Web site:

Microsoft is currently investigating a reported vulnerability in Microsoft ASP.NET. An attacker can send specially crafted requests to the server and view secured content without providing the proper credentials. This reported vulnerability exists in ASP.NET and does not affect ASP.

This issue affects Web content owners who are running any version of ASP.NET on Microsoft Windows 2000, Windows 2000 Server, Windows XP Professional, and Windows Server 2003.

The underlying issue is that ASP.NET is failing to perform proper canonicalization of some URLs. Microsoft Knowledge Base (KB) article 887459, "Programmatically Checking for Canonicalization Issues with ASP.NET," describes how to add additional safeguards to an ASP.NET application to help protect against common canonicalization issues, such as those related to this reported vulnerability.

Resources
    
http://www.microsoft.com/security/incident/aspnet.mspx
    
http://support.microsoft.com/?kbid=887459

Both DotNetJunkies and SqlJunkies have been patched.

MSN Search & Research

I spent a couple days this week with the MSN Search team and MS Research looking at what they are doing with search, and how they plan to compete in the Top-3 dominated search market (Google, Yahoo, MSN). Over all I was very impressed with what they are doing and what their goals are - although I can't share either of those things due to the NDA I signed.

What I can do though is point you to some public resources that they shared with us.

MSN Searc Technology Preview 2
This is a beta version of the new MSN Search. Try it out and provide your feedback.

Lookout
This is the popular Lookout toll that MSFT recently purchased. You can use it to search your email.

Wallop
A Social Computing Web site that links people together through all kinds of crazy algorythms and data.