Handled and unhandled errors
The error pages should be consistent throughout the whole system. Configuring different error pages for handled errors and unhandled errors (a page redirected by ASP.NET using the <customErrors> web.config key) can be a severe security risk.
You should have only one error page for both of these cases. Find more information in the Creating custom error handling pages topic.
The time needed for processing a page after encountering an error can be considerably different from the processing time in other cases. The attackers can use this difference to guess if their input has caused any problems in the system.
There is no general recommendation on how to solve this trouble. However, you can try to provide some malicious input yourself and observe how much time it takes the system to complete the request. This way, you can find weaknesses in the system.
Instead of showing detailed information about the problem in the error message, store the debug data and stack trace into the event log.
To configure the system to display custom error messages, modify the web.config file, as described in the Web.config file settings topic.