11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

392 Part III: Building Secure <strong>Web</strong> <strong>Application</strong>sUse a Generic Error Page in Your ASP.NET <strong>Application</strong>sIf your data access code is called by an ASP.NET <strong>Web</strong> application or <strong>Web</strong> service,you should configure the element to prevent exception detailspropagating back to the end user. You can also specify a generic error page by usingthis element, as shown below.Set mode=“On” for production servers. Only use mode=“Off” when you aredeveloping <strong>and</strong> testing software prior to release. Failure to do so results in rich errorinformation, such as that shown in Figure 14.4, being returned to the end user. Thisinformation can include the database server name, database name, <strong>and</strong> connectioncredentials.Figure 14.4Detailed exception information revealing sensitive data

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!