Web Hack List

Other nomination

Deep understand ASPX file handling and some related attack vectors

Reverse-engineers how IIS compiles ASPX pages into cached DLLs under Temporary ASP.NET Files, including the code generation directory and the eight-character cache key algorithms. An attacker able to write there plants a backdoor DLL that hijacks a page without touching webroot, tampers across application pools that share one identity group, or reaches filtered URLs by cache key collision.

Record

Researcher
@rskvp93 and rskvp93
Published by
Blog of Viettel Cyber Security
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @rskvp93 and rskvp93, first published at the original source. Preserved copies are kept so the citation survives its host.