Reading ASP secrets for $17,000
samcurry.net | blog | #bug-bounty | #web-security | #path-traversal | #aspnet | #local-file-disclosure | #source-code-disclosure
Summary
Turning local file disclosure on an ASP.NET app into a $17,000 bounty: reading download.aspx source, bypassing the two-dot traversal block, and hunting server-side secrets with the widened access.
- Published
- Collected
Skip to content