More on .Old
While discussing the afore-mentioned "system" of keeping track of changes with a friend, she mentioned (she used to deal with intrusion detection for web apps) that she broke several system by systematically trying "Page.aspx.old", "Page.aspx.tmp", "Page2.aspx", etc for all the pages in the application. The booty was usually the page source, and in most cases, that came along with the full (unencrypted, naturally) connection string, including the "sa" password.
What was your experiance?
Comments
Comment preview