ASP.NET error message

Description

By requesting a specially crafted URL is possible to generate an ASP.NET error message. The message contains the complete stack trace and Microsoft .NET Framework Version.

Remediation

Adjust web.config to enable custom errors for remote clients. Set customErrors mode to RemoteOnly. customErrors is part of system.web Element. RemoteOnly specifies that custom errors are shown only to the remote clients, and that ASP.NET errors are shown to the local host. This is the default value.

<configuration>
    <system.web>
      <customErrors mode="RemoteOnly" />
  </system.web>
</configuration>

References