The following tips are simple, yet effective to maintain a portion of ASP.NET application security.
Web.config vulnerabilities: Default Error Message
When custom errors are disabled, ASP.NET gives a detailed default error message to clients.
Vulnerable configuration:
<configuration>
<system web>
<customErrors mode="off">
Secure configuration:
<configuration>
<system web>
<customErrors mode="remote only">