Dangers of Custom ASP.NET HttpHandlers
ID: 1cc56b3b-5d71-58fe-a855-a7465d74b3c7
STIX ID: report--1cc56b3b-5d71-58fe-a855-a7465d74b3c7
Feed Name: SensePost Blog
This blog post demonstrates a security flaw in Telerik's ASP.NET ChartImage.axd handler where the ImageName parameter is encrypted with AES using a key and IV embedded in Telerik.Web.UI.dll, enabling an attacker who extracts those values to request arbitrary files (which the handler may then delete after download). The post includes decompiled code, affected version information (pre-2011.2.915.35), a proof-of-concept, and a recommendation to update the Telerik.Web.UI.dll to a patched version.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
