Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Reading ASP secrets for $17,000

Summary

Turning local file disclosure on an ASP.NET app into a $17,000 bounty: reading download.aspx source, bypassing the two-dot traversal block, and hunting server-side secrets with the widened access.
Published
Collected

original ↗

Related coverage

back