3 ms·
> The web page used an old .NET framework that serialized the application state, base64 encoded it, then dumped it in a hidden form field at the bottom. Wow. I
by damagednoob 5y ago
> The web page used an old .NET framework that serialized the application state, base64 encoded it, then dumped it in a hidden form field at the bottom.
Wow. I was a C# developer for many years and I never realised that ViewState encryption was _opt in_[1].
[1] https://docs.microsoft.com/en-us/previous-versions/aspnet/bb386448(v=vs.100)#encrypting-view-state https://docs.microsoft.com/en-us/previous-versions/aspnet/bb...
- tragictrash 5y agoSomeone interviewed for my company last month. One of his previous experiences was listed as "dynamic SQL". My third question was how do you prevent SQL injection attacks. He didn't know.
- ceejayoz 5y agoTo be fair, leaving a SQL injection hole makes it pretty dynamic.
- tragictrash 5y agoWow. That's the real 10x developer play. New api? Why, we have that one endpoint!
- chewbacha 5y agoThat’s basically what Postgraphql is.
- DarylZero 5y agoBlame your own process, that guy was doing the right thing to get interviews.
- habeebtc 5y agoWoah. I did not realize that either. It would be trivial to loose a bot on government TLD's and see who else is putting unencrypted PII in their viewstate.
- donmcronald 5y ago> If those identifiers contain sensitive data, such as customer IDs, you should encrypt the view state data in addition to or instead of sending the page over SSL. It would be hilarious if those docs got updated to say customer IDs or SSNs. Lol. The craziest part is that if you had made that same mistake and leaked a bunch of SSNs the same government would be fining you and accusing you of being negligent. It's insane.