?
Solved

Is there a way to configure the timeout value of the __VIEWSTATE hidden variable

Posted on 2008-02-06
1
Medium Priority
?
696 Views
Last Modified: 2012-06-27
A developer found a work-around that allowed him to use the __VIEWSTATE parameter to pass login information from their domain to ours and then bypass our login.  See code below:

-------------------------------
 <form name="_ctl0" method="post" target="_blank"
action="http://www.scitationreports.org/Login.aspx?ReturnUrl=default.asp
x"
id="_ctl0">

   <input type="hidden" name="__VIEWSTATE"
value="dDwtNjgyOTcyODA0OztsPFJlbWVtYmVyTWU7Pj4MNmkUWpCOIvjPMIfBnAch6P/0n
g==" />

   <input type="hidden" name="txtUsername" value="<%=username%>"
id="txtUsername" />
   <input type="hidden" name="txtPassword" value="<%=password%>"
id="txtPassword" />
   <input class="btn" onmouseover="this.className='btnhov'"
onmouseout="this.className='btn'" type="submit" name="_ctl3" value="View Usage Reports" />
   <!--<a href="#" onClick="document._ctl0.submit()">Login to see Report</a><br><br>-->
   </form>
-------------------------------

The above workaround would work for approximately a month at which point the _VIEWSTATE value would need to be updated.  But when we upgraded from Windows 2000/IIS5 to Win2003/IIS6 the developer is now having to change the value daily.

We are trying to find the easiest way to accomodate this requirement without any code changes to our site.  Is there a way we can increase the life of the __VIEWSTATE variable?  

Thanks
0
Comment
Question by:TheShaner
1 Comment
 
LVL 27

Accepted Solution

by:
mrcoffee365 earned 1500 total points
ID: 20843365
As far as I can tell, ViewState is a page variable that has no relation to session timeout.  You can write code which attaches ViewState to the Session State, and change your ASPX pages to get ViewState from the session.

There are occasions in IIS6 when the saved ViewState on the server will go away -- when the application pool is refreshed.  That might be what you're seeing.  See this article from Microsoft on possible causes of invalid ViewState (you don't give the error that your developer sees, so I can't tell if this is the case for you):
http://support.microsoft.com/kb/555353
0

Featured Post

Never miss a deadline with monday.com

The revolutionary project management tool is here!   Plan visually with a single glance and make sure your projects get done.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The first step to building an amazing About page is to figure out what you want the page to say about your company. You then must grab the attention of the reader, boast a bit, tell a story and let others brag about you. With a little bit of thought…
Over time, the online landscape has altered considerably, but that’s nothing compared to the up-and-coming trends that will shape the web design industry in the coming year. Keep reading to find out which trends will shape B2B web design in 2018.
Explain concepts important to validation of email addresses with regular expressions. Applies to most languages/tools that uses regular expressions. Consider email address RFCs: Look at HTML5 form input element (with type=email) regex pattern: T…
This video teaches users how to migrate an existing Wordpress website to a new domain.
Suggested Courses
Course of the Month3 days, 21 hours left to enroll

599 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question