[WEB SECURITY] event validation in ASP.NET

Cheong Kai Wee ckw214 at yahoo.com
Mon Dec 10 01:38:57 EST 2012


Hi All,

May I know if there is any tool that can assist in manipulating ASP.net _EVENTVALIDATION parameter? For _VIEWSTATE, i am able to manipulate using tools such as fiddler viewstate viewer. 


For _EVENTVALIDATION, the same tool can still be used to serialize/deserialize the parameter. However, it doesn't help in generating a valid hash value that i wish to add. I am looking for similar tool like "EventValidation Tool" in this tutorial: http://www.jardinesoftware.net/2012/02/06/asp-net-tampering-with-event-validation-part-1/ . It will also be helpful if anyone can point out the hashing algorithm used in _EVENTVALIDATION, in this case i can generate the hash value manually.

Thanks. :)

Cheers,
Kai Wee
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/attachments/20121209/23430c91/attachment-0003.html>


More information about the websecurity mailing list