4 ms·
Yup, ASP's "__VIEWSTATE" hidden form parameter comes to mind. It was base64-encoded and POSTed because it could get loooong (hundreds of KB). Terrible for brow
by rbinv 1y ago
Yup, ASP's "__VIEWSTATE" hidden form parameter comes to mind. It was base64-encoded and POSTed because it could get loooong (hundreds of KB).
Terrible for browser navigation/refresh though, because pretty much everything was a form POST. Thus no URL state sharing, either.
- bux93 1y agoAlso a terrible idea to execute code from the client, even if it's supposedly signed. https://darkatlas.io/blog/critical-sharepoint-vulnerability-cve-2025-53770-remote-code-execution-via-viewstate-abuse https://darkatlas.io/blog/critical-sharepoint-vulnerability-...