Click here to Skip to main content
13,594,074 members
Click here to Skip to main content
Add your own
alternative version

Tagged as


2 bookmarked
Posted 27 Oct 2010
Licenced CPOL


, 27 Oct 2010
Rate this:
Please Sign up or sign in to vote.
In this trick I present how to prevent an attack by a hacker on website.
On, the hidden Parameter __VIEWSTATE is passed each PostBack,So
if you've misconfigured your site and if a malicious user puts in the url: am hacker
the site goes down and worse could it be the code of the aspx page.

So when you try this on ASP.NET 2.0 WebSite:!

You will have something like this:

Server Error in '/' Application. Runtime Error
Description: An application error occurred on the server. The current custom error settings for this application prevent the details of the application error from being viewed remotely (for security reasons). It could, however, be viewed by browsers running on the local server machine

Details: To enable the details of this specific error message to be viewable on remote machines, please create a tag within a "web.config" configuration file located in the root directory of the current web application. This tag should then have its "mode" attribute set to "Off"

the Solution is to Remove __VIEWSTATE parameter From Request.QueryString

protected override void OnInitComplete(EventArgs e)
            if (Request.QueryString.ToString().Contains("__VIEWSTATE"))
            {// reflect to readonly
               propertyPropertyInfo isreadonly = typeof(System.Collections.Specialized.NameValueCollection).GetProperty("IsReadOnly", BindingFlags.Instance | BindingFlags.NonPublic);
                // make collection editable
                isreadonly.SetValue(this.Request.QueryString, false, null);
                // remove
                // make collection readonly again
                isreadonly.SetValue(this.Request.QueryString, true, null);


This article, along with any associated source code and files, is licensed under The Code Project Open License (CPOL)


About the Author

kadaoui el mehdi
Belgium Belgium
in 2005, I started my career. Net and I could improve in this technology through the project WinFroms. Net 2.0 / MVC2 for "Nestle".

After obtaining my diploma MASTER "MBDS" from the University of Nice Sophia Anti-police, I left to Belguim to work as Expert .Net Analyst Developer.

Currently I specialize in architecture to the lowest level.

Meanwhile I remain very active in the community. Net, I created the 1st community. Net Morocco "on Facebook and LinkedIn and twitter, called "Morocco .Net User Group (MONUG)"

You may also be interested in...

Comments and Discussions

GeneralReason for my vote of 1 "the site goes down" No, that single... Pin
Richard Deeming2-Nov-10 7:33
memberRichard Deeming2-Nov-10 7:33 
GeneralI think that the best place to do that, it's to create an Ht... Pin
kadaoui el mehdi28-Oct-10 6:05
memberkadaoui el mehdi28-Oct-10 6:05 
GeneralHi Kadaoui Where should this code be place? on every page t... Pin
Anton Pretorius28-Oct-10 1:06
memberAnton Pretorius28-Oct-10 1:06 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.

Permalink | Advertise | Privacy | Cookies | Terms of Use | Mobile
Web04-2016 | 2.8.180618.1 | Last Updated 27 Oct 2010
Article Copyright 2010 by kadaoui el mehdi
Everything else Copyright © CodeProject, 1999-2018
Layout: fixed | fluid