Tony Carter posted on September 28, 2010 01:07

Microsoft announced a critical ASP.NET security vulnerability. There has been workarounds provided and an out-of-band update is scheduled to be released this week via Windows Update.
The vulnerability exploits a flaw in the way error messages are reporting back to an requesting client. The exploit can allow a hacker to obtain web.config and other sensitive files that would not be accessible normally. Also, the hacker can use the exploit to decrypt data being transferred between the web server and any client. The exploit pertains to all versions of ASP.NET, DotNetNuke and SharePoint platforms.
If you do not have control of the servers your websites are running on, you can implement a temporary workaround until the server is patched.
I have posted the link to the entire article and workaround.
ASP.NET Security Vulnerability and Workaround