11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 10: Building Secure ASP.NET Pages <strong>and</strong> Controls 297Additional ResourcesFor more information, see the following resources:●●●●●●●●●For information about establishing a secure Machine.config <strong>and</strong> <strong>Web</strong>.configconfiguration, see Chapter 19, “Securing Your ASP.NET <strong>Application</strong> <strong>and</strong> <strong>Web</strong>Services.”For a printable checklist, see “Checklist: Securing ASP.NET” in the “Checklists”section of this guide.For information on securing your developer workstation, see “How To: SecureYour Developer Workstation” in the “How To” section of this guide.For more information on authentication <strong>and</strong> authorization in ASP.NET, seeChapter 8, “ASP.NET <strong>Security</strong>,” in “Microsoft patterns & practices Volume I,Building Secure ASP.NET <strong>Application</strong>s: Authentication, Authorization, <strong>and</strong> SecureCommunication” at http://msdn.microsoft.com/library/en-us/dnnetsec/html/SecNetch08.asp.For walkthroughs of using Forms Authentication, see “How To: Use FormsAuthentication with SQL Server 2000” <strong>and</strong> “How To: Use Forms Authenticationwith Active Directory”, in the “How To” section of “Microsoft patterns & practicesVolume I, Building Secure ASP.NET <strong>Application</strong>s: Authentication, Authorization, <strong>and</strong>Secure Communication” at http://msdn.microsoft.com/library/en-us/dnnetsec/html/SecNetHT00.asp.For more information about using regular expressions, see Microsoft KnowledgeBase article 308252, “How To: Match a Pattern by Using Regular Expressions <strong>and</strong>Visual C# .NET.”For more information about user input validation in ASP.NET, see MSDNarticle “User Input Validation in ASP.NET” at http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnaspp/html/pdc_userinput.asp.For more information about the Secure cookie property, see RFC2109 on theW3C <strong>Web</strong> site at http://www.w3.org/Protocols/rfc2109/rfc2109.For more information on security considerations from the Open Hack competition,see MSDN article “Building <strong>and</strong> Configuring More Secure <strong>Web</strong> Sites” athttp://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnnetsec/html/openhack.asp.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!