Blog Stats
  • Posts - 14
  • Articles - 2
  • Comments - 5
  • Trackbacks - 5

 

One-click attack:How to prevent them?

One click attack normally occurs when attacker creates  a prefilled web page(.htm or .aspx) with view state. The view state is generated from a previously created page. ex. shopping cart page with say 50 items. The attacker then lures unsususpecting user to browse the page and causing the page to be sent to server where view state is valid.

To prevent this kind of attack in .NET, use Page.ViewStateUserKey in Page_Init event with unique value per user such as username or configured in web.config.


Feedback

# Магия VooDoo

Gravatar Спасибо Яндексу, именно благодаря ему я нашла этот замечательный форум.
Думаю здесь я останусь надолго. 3/21/2009 1:03 PM | DoonHadakeeta

# orassegulgeradia повелевай миром 9

Gravatar hello, where are you out a such DIZ? 4/5/2009 4:46 AM | SMS_Inonse

# pewi.ru

Gravatar PEWI - Web2.0 Hand Made ~ Creative, Design, Art, Music, Movie ~ http://pewi.ru/1.htm 11/17/2009 6:22 AM | BictCuccist

Post a comment





 

 

 

Copyright © Parmeshwar Arewar