MVC2 Cookieless Session Issue using POST

后端 未结 3 2025
不思量自难忘°
不思量自难忘° 2020-12-10 09:35

For some reason with cookieless session enabled in MVC2, the session id in the query string is reset with every form post that happens. Is there a special route that needs t

3条回答
  •  刺人心
    刺人心 (楼主)
    2020-12-10 09:55

    Microsoft Security Bulletin MS10-070 - Important: Vulnerability in ASP.NET Could Allow Information Disclosure (2418042)

    If installed this update, check this KB.

    Http.sys registry settings for IIS

    Use cookieless session & form authentication auto insert this("/(S(...)F(...))/") Url path segment. Default UrlSegmentMaxLength is 260, but MS10-070 installed environment over this.I think it is a result for padding oracle.

    Hope this help!

提交回复
热议问题