| |
A security researcher describes how to decrypt encrypted ASP.NET view state messages using automatically generated (autogen) keys extracted from Windows registry or LSA secrets. The post outlines the technical process for deriving final machine keys from autogen keys for both legacy and modern cryptographic configurations, addressing a practical challenge where investigators found encrypted malicious view state in application logs but lacked the decryption capability. The author also introduces a new tool to simplify view state decryption, which has historically required using either CyberChef or reflection-based approaches.
Read Full Article →
← More Tech news