Mon Jul 19, 2010 9:15 am

Bypassing ASP.NET ValidateRequest Filters

I regularly test websites which appear to be hosted on upto date (patched) web servers. The only bypass i have found is <~/XSS/*-*/STYLE=xss:e/**/xpression(alert('XSS')) but doesnt appear to work anymore! Reading the whitepaper from Procheckup they had the following test environment:

Microsoft Windows Server 2003 R2 Standard Edition Build 3790.srv03_sp2_gdr.070304-2240 : Service Pack 2 (patched Aug 08) running Microsoft IIS 6.0 web server ASP.NET Version: 1.1.4322.2407 (fully patched) ASP.NET Version: 2.0.50727 (fully patched Aug 2008) Microsoft Internet Explorer 6.0.2800.1106 Microsoft Internet Explorer 7.0.5730.13

This was 2 years ago.... anyone got anything upto date sicne most environments SHOULD have been patched since then!