11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

9Using Code Access <strong>Security</strong>with ASP.NETIn This Chapter●●●●●●OverviewConfiguring <strong>Web</strong> application trust levels <strong>and</strong> ASP.NET code access security policyDeveloping partial-trust <strong>Web</strong> applicationsS<strong>and</strong>boxing privileged codeWriting to the event log from medium-trust <strong>Web</strong> applicationsCalling OLE DB data sources from medium-trust <strong>Web</strong> applicationsCalling <strong>Web</strong> services from medium-trust <strong>Web</strong> applicationsCode access security is a resource constraint model that allows administrators todetermine if <strong>and</strong> how particular code is able to access specified resources <strong>and</strong>perform other privileged operations. For example, an administrator might decide thatcode downloaded from the Internet should not be given permission to access anyresources, while <strong>Web</strong> application code developed by a particular company should beoffered a higher degree of trust <strong>and</strong>, for example, be allowed to access the file system,the event log, <strong>and</strong> Microsoft SQL Server databases.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!