Microsoft Threat Intelligence has identified a limited attack campaign leveraging publicly available ASP.NET machine keys to conduct ViewState code injection attacks. The attacks, first observed late last year, involved an unknown attacker using a static ASP.NET machine key to inject malicious code and deploy the Godzilla post exploitation framework , which allows attackers to execute commands and inject shellcode on compromised servers. ViewState is a mechanism in ASP.NET Web Forms that...

Read the full article at RedmondMag.com