Microsoft .NET and Security Provided by High -Level Internet Protocols

Tatiana Melnik, Zornitza Genova Prodanoff · University of North Florida Digital Commons (University of North Florida) · 2005

This paper describes a class of insecure .NET client applications, which avoid higher layer protocol protection through using a “raw” send and receive API. The .NET Framework rests on many other Microsoft components, including the Windows Driver Model (WDM). This model supports four driver types, two of which were considered in this paper: protocol and miniport drivers. By compiling and executing client applications using the “raw” sockets interface, we demonstrate that insecure clients can be written with minimal programming effort (lines of code).

Read the paper · More papers on PaperTik