About this tag
The errorpage tag on WindowsForum.com covers discussions about custom error pages in ASP.NET, particularly in the context of security advisories. A notable thread references Microsoft Security Advisory 2416728, which addresses a vulnerability in ASP.NET that could lead to information disclosure. The advisory recommends enabling ASP.NET custom errors and mapping all error codes to the same error page as a workaround. This tag is relevant for developers and IT professionals managing ASP.NET applications, focusing on how error page configurations can mitigate security risks. Topics include implementing custom error handling, URL scanning, and request filtering to protect sensitive data.
-
Microsoft Security Advisory (2416728): Vulnerability in ASP.NET Could Allow Information Disclosure -
Revision Note: V1.2 (September 24, 2010): Added an entry to the FAQ to announce a revision to the workaround, "Enable a UrlScan or Request Filtering rule, enable ASP.NET custom errors, and map all error codes to the same error page." Customers who have already applied the workaround should...- News
- Thread
- active attacks advisory asp.net customerrors encryption errorpage faq information information disclosure microsoft request filtering security security breach server issues tampering urlscan viewstate vulnerability web.config workaround
- Replies: 0
- Forum: Security Alerts