11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 9: Using Code Access <strong>Security</strong> with ASP.NET 233Table 9.3 identifies the permissions that each ASP.NET trust level grants. The fulllevel is omitted from the table because it grants all of the permissions in theirunrestricted state.Table 9.3 Default ASP.NET Policy Permissions <strong>and</strong> Trust LevelsPermission <strong>and</strong> State High Medium Low MinimalAspNetHostingLevel High Medium Low MinimalDnsPermissionUnrestricted EnvironmentPermissionUnrestrictedReadWriteTEMP; TMP;USERNAME; OS;COMPUTERNAMEEventLogPermissionFileIOPermissionUnrestrictedReadWriteAppendPathDiscovery$AppDir$$AppDir$$AppDir$$AppDir$$AppDir$$AppDir$IsolatedStorageFilePermissionUnrestrictedAssemblyIsolationByUser-Unrestricted UserQuota1MB(can varywith site)OleDbClientPermissionUnrestrictedPrintingPermissionUnrestrictedDefaultPrinting ReflectionPermissionUnrestrictedReflectionEmitRegistryPermissionUnrestricted(continued)

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!