{"id":668,"date":"2010-09-23T19:57:00","date_gmt":"2010-09-23T19:57:00","guid":{"rendered":"https:\/\/brainlitter.itgroove.net\/2010\/09\/23\/major-aspnet-vulnerability\/"},"modified":"2010-09-23T19:57:00","modified_gmt":"2010-09-23T19:57:00","slug":"major-aspnet-vulnerability","status":"publish","type":"post","link":"https:\/\/regroove.ca\/brainlitter\/2010\/09\/23\/major-aspnet-vulnerability\/","title":{"rendered":"Major ASP.NET Vulnerability"},"content":{"rendered":"<div class=\"ExternalClassDBCD0596EAAB4E14B966B0D585C72BCE\">\n<p><span style=\"font-family:Verdana;font-size:10pt\">To our valued clients, <\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family:Verdana;font-size:10pt\">itgroove wants to let you know about an important security risk that has been discovered. <\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family:Verdana;font-size:10pt\">Microsoft has advised it partners and customers worldwide of a vulnerability in one of the backend fundamental components of SharePoint \u2013 asp.net \u2013 that can allow an attacker to penetrate and manipulate SharePoint installations.\u00a0 The vulnerability affects all versions of SharePoint from version 2 through WSS\/MOSS (SharePoint 3) and SharePoint 2010.\u00a0 The vulnerability is considered so severe that Microsoft has issued a set of instructions on how to hand-code a workaround to close the vulnerability.\u00a0 This is NOT a patch, it requires the actual editing of some of the backend configuration files within SharePoint. <\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family:Verdana;font-size:10pt\">We believe this to be a severe enough vulnerability that we are advising all of our customers of the problem and we urge you to contact us to arrange a time when we can make the required changes for you.\u00a0 The work involved should only take about 30 minutes but once the change is made an IISreset will be required which will cause a short disruption in SharePoint availability. <\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family:Verdana;font-size:10pt\">As well here is a link to instructions for those who have the knowledge and experience to implement this workaround: <a href=\"http:\/\/blogs.msdn.com\/b\/wp-content\/uploads\/brainlitter\/brainlitterarchive\/sharepoint\/archive\/2010\/09\/21\/security-advisory-2416728-vulnerability-in-asp-net-and-sharepoint.aspx\"><span style=\"color:#333333\">http:\/\/blogs.msdn.com\/b\/wp-content\/uploads\/brainlitter\/brainlitterarchive\/sharepoint\/archive\/2010\/09\/21\/security-advisory-2416728-vulnerability-in-asp-net-and-sharepoint.aspx<\/span><\/a> <\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family:Verdana;font-size:10pt\">Please contact us at 250-220-4575 to make arrangements or to get more information. <\/span><\/p>\n<p>\u00a0<\/p>\n<p><span style=\"font-family:Verdana;font-size:10pt\">Your SharePoint support team at itgroove. <\/span><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>To our valued clients, \u00a0 itgroove wants to let you know about an important security risk that has been discovered. \u00a0 Microsoft has advised it partners and customers worldwide of a vulnerability in one of the backend fundamental components of SharePoint \u2013 asp.net \u2013 that can allow an attacker to penetrate and manipulate SharePoint installations.\u00a0 &hellip; <a href=\"https:\/\/regroove.ca\/brainlitter\/2010\/09\/23\/major-aspnet-vulnerability\/\"><\/a><\/p>\n","protected":false},"author":10,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":"","_jetpack_memberships_contains_paid_content":false},"categories":[433,5,337,436,14,334,338,222,339],"tags":[],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Major ASP.NET Vulnerability - Brainlitter - Inside the mind of Sean Wallbridge<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/regroove.ca\/brainlitter\/2010\/09\/23\/major-aspnet-vulnerability\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Major ASP.NET Vulnerability - Brainlitter - Inside the mind of Sean Wallbridge\" \/>\n<meta property=\"og:description\" content=\"To our valued clients, \u00a0 itgroove wants to let you know about an important security risk that has been discovered. \u00a0 Microsoft has advised it partners and customers worldwide of a vulnerability in one of the backend fundamental components of SharePoint \u2013 asp.net \u2013 that can allow an attacker to penetrate and manipulate SharePoint installations.\u00a0 &hellip;\" \/>\n<meta property=\"og:url\" content=\"http:\/\/regroove.ca\/brainlitter\/2010\/09\/23\/major-aspnet-vulnerability\/\" \/>\n<meta property=\"og:site_name\" content=\"Brainlitter - Inside the mind of Sean Wallbridge\" \/>\n<meta property=\"article:published_time\" content=\"2010-09-23T19:57:00+00:00\" \/>\n<meta name=\"author\" content=\"Sean Wallbridge\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sean Wallbridge\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"http:\/\/regroove.ca\/brainlitter\/2010\/09\/23\/major-aspnet-vulnerability\/\",\"url\":\"http:\/\/regroove.ca\/brainlitter\/2010\/09\/23\/major-aspnet-vulnerability\/\",\"name\":\"Major ASP.NET Vulnerability - Brainlitter - Inside the mind of Sean Wallbridge\",\"isPartOf\":{\"@id\":\"https:\/\/regroove.ca\/brainlitter\/#website\"},\"datePublished\":\"2010-09-23T19:57:00+00:00\",\"dateModified\":\"2010-09-23T19:57:00+00:00\",\"author\":{\"@id\":\"https:\/\/regroove.ca\/brainlitter\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77\"},\"breadcrumb\":{\"@id\":\"http:\/\/regroove.ca\/brainlitter\/2010\/09\/23\/major-aspnet-vulnerability\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\/\/regroove.ca\/brainlitter\/2010\/09\/23\/major-aspnet-vulnerability\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\/\/regroove.ca\/brainlitter\/2010\/09\/23\/major-aspnet-vulnerability\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Brainlitter\",\"item\":\"https:\/\/regroove.ca\/brainlitter\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Major ASP.NET Vulnerability\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/regroove.ca\/brainlitter\/#website\",\"url\":\"https:\/\/regroove.ca\/brainlitter\/\",\"name\":\"Brainlitter - Inside the mind of Sean Wallbridge\",\"description\":\"Dad. Husband. Drummer. Learner of Things.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/regroove.ca\/brainlitter\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/regroove.ca\/brainlitter\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77\",\"name\":\"Sean Wallbridge\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/regroove.ca\/brainlitter\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g\",\"caption\":\"Sean Wallbridge\"},\"url\":\"https:\/\/regroove.ca\/brainlitter\/author\/swallbridge\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Major ASP.NET Vulnerability - Brainlitter - Inside the mind of Sean Wallbridge","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/regroove.ca\/brainlitter\/2010\/09\/23\/major-aspnet-vulnerability\/","og_locale":"en_US","og_type":"article","og_title":"Major ASP.NET Vulnerability - Brainlitter - Inside the mind of Sean Wallbridge","og_description":"To our valued clients, \u00a0 itgroove wants to let you know about an important security risk that has been discovered. \u00a0 Microsoft has advised it partners and customers worldwide of a vulnerability in one of the backend fundamental components of SharePoint \u2013 asp.net \u2013 that can allow an attacker to penetrate and manipulate SharePoint installations.\u00a0 &hellip;","og_url":"http:\/\/regroove.ca\/brainlitter\/2010\/09\/23\/major-aspnet-vulnerability\/","og_site_name":"Brainlitter - Inside the mind of Sean Wallbridge","article_published_time":"2010-09-23T19:57:00+00:00","author":"Sean Wallbridge","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sean Wallbridge","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"http:\/\/regroove.ca\/brainlitter\/2010\/09\/23\/major-aspnet-vulnerability\/","url":"http:\/\/regroove.ca\/brainlitter\/2010\/09\/23\/major-aspnet-vulnerability\/","name":"Major ASP.NET Vulnerability - Brainlitter - Inside the mind of Sean Wallbridge","isPartOf":{"@id":"https:\/\/regroove.ca\/brainlitter\/#website"},"datePublished":"2010-09-23T19:57:00+00:00","dateModified":"2010-09-23T19:57:00+00:00","author":{"@id":"https:\/\/regroove.ca\/brainlitter\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77"},"breadcrumb":{"@id":"http:\/\/regroove.ca\/brainlitter\/2010\/09\/23\/major-aspnet-vulnerability\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/regroove.ca\/brainlitter\/2010\/09\/23\/major-aspnet-vulnerability\/"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/regroove.ca\/brainlitter\/2010\/09\/23\/major-aspnet-vulnerability\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Brainlitter","item":"https:\/\/regroove.ca\/brainlitter\/"},{"@type":"ListItem","position":2,"name":"Major ASP.NET Vulnerability"}]},{"@type":"WebSite","@id":"https:\/\/regroove.ca\/brainlitter\/#website","url":"https:\/\/regroove.ca\/brainlitter\/","name":"Brainlitter - Inside the mind of Sean Wallbridge","description":"Dad. Husband. Drummer. Learner of Things.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/regroove.ca\/brainlitter\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/regroove.ca\/brainlitter\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77","name":"Sean Wallbridge","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/regroove.ca\/brainlitter\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g","caption":"Sean Wallbridge"},"url":"https:\/\/regroove.ca\/brainlitter\/author\/swallbridge\/"}]}},"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/regroove.ca\/brainlitter\/wp-json\/wp\/v2\/posts\/668"}],"collection":[{"href":"https:\/\/regroove.ca\/brainlitter\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/regroove.ca\/brainlitter\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/regroove.ca\/brainlitter\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/regroove.ca\/brainlitter\/wp-json\/wp\/v2\/comments?post=668"}],"version-history":[{"count":0,"href":"https:\/\/regroove.ca\/brainlitter\/wp-json\/wp\/v2\/posts\/668\/revisions"}],"wp:attachment":[{"href":"https:\/\/regroove.ca\/brainlitter\/wp-json\/wp\/v2\/media?parent=668"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/regroove.ca\/brainlitter\/wp-json\/wp\/v2\/categories?post=668"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/regroove.ca\/brainlitter\/wp-json\/wp\/v2\/tags?post=668"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}