Hacking and Security / Re: Problem with "Asp.net padding oracle vulnerability"
« on: January 24, 2014, 05:51:07 PM »
Well, A.NPO, is a vulnerability VERY dificult to find today..., and for SURE this is a false positive, because Acunetix 8 don't scan for REAL the Encrypted Code on WebResource, if the custom_error is Active or Not, If the EBC or CBC Decrypt is REALLY Vulnerable, Well, Acunetix is Horrible today, Use Good Vul Scanners, like: w3fc, Nikto, Nessus, OWASP ZAP(Is a Fuzzer Too , and well, For Sure is a False Positive.