28.12.2013 Views

Building Secure ASP.NET Applications - People Search Directory

Building Secure ASP.NET Applications - People Search Directory

Building Secure ASP.NET Applications - People Search Directory

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

xxiv<br />

<strong>Building</strong> <strong>Secure</strong> <strong>ASP</strong>.<strong>NET</strong> <strong>Applications</strong><br />

Contributors and Reviewers<br />

Many thanks to the following contributors and reviewers:<br />

●<br />

●<br />

●<br />

●<br />

Thanks to external reviewers – Keith Brown (DevelopMentor) for review and<br />

feedback on the <strong>ASP</strong>.<strong>NET</strong> chapter, Andy Eunson for providing scenarios on<br />

middleware applications, John Langley (KANA Software) for bringing J2EE<br />

and .<strong>NET</strong> perspectives to the table, Kurt Dillard and Christof Sprenger for<br />

reviewing application scenarios and the authentication and authorization<br />

process, J.K.Meadows and David Alberto for reviewing application scenarios<br />

and individual chapters and Bernard Chen (Sapient) for reviewing the<br />

authentication and authorization process<br />

Product Group – Thanks to Manish Prabhu, Jesus Ruiz-Scougall, Jonathan<br />

Hawkins and Doug Purdy from the .<strong>NET</strong> Remoting team; Keith Ballinger Yann<br />

Christensen and Alexei Vopilov from the Web Services team; Laura Barsan from<br />

the <strong>ASP</strong>.<strong>NET</strong> team; Greg Fee (.<strong>NET</strong> Roles / Principal permission checks), Greg<br />

Singleton and Sebastian Lange (CAS); Tarik Soulami from the CLR team; Erik<br />

Olson (extensive validation and recommendations on <strong>ASP</strong>.<strong>NET</strong>); Caesar Samsi<br />

(for sharing in depth e-commerce Internet facing application scenarios), Riyaz<br />

Pishori, Shannon Pahl and Ron Jacobs (Enterprise Services), Dave McPherson<br />

(Windows security architecture and authorization strategies), Christopher Brown<br />

(helping resolve cross product issues), John Banes (DPAPI), Joel Scambray, Girish<br />

Chander (SQL Server security)<br />

MCS / Field – William Zentmayer (Remote application tier scenarios with Enterprise<br />

Services), Shantanu Sarkar (validation of application architecture scenarios),<br />

Carl Nolan (Web services), Samuel Melendez and Jacquelyn Schmidt<br />

(infrastructure and deployment scenarios), Steve Busby, Len Cardinal, Monica<br />

DeZulueta, Paula Paul (Data Access and Web application security), Ed Draper,<br />

Sean Finnegan (pushing Active <strong>Directory</strong> and Windows authentication with<br />

technical depth and practical scenarios), David Alberto, Kenny Jones (for bringing<br />

real world field issues to the table and helping to involve the field), Doug<br />

Orange (real world Extranet authorization scenarios), Alexey Yeltsov (SQL<br />

Injection), Martin Kohlleppel (Architecture review), Joel Yoker (firewalls and<br />

IPSec)<br />

Special thanks to Jay Nanduri (Microsoft.com) for reviewing and sharing real<br />

world experiences, Ilia Fortunov (Senior Architect) for providing continuous and<br />

diligent feedback and Aaron Margosis (MCS) for thoroughly reviewing several<br />

chapters and making excellent suggestions at various stages of the project.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!