11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

19Securing Your ASP.NET <strong>Application</strong><strong>and</strong> <strong>Web</strong> ServicesIn This Chapter●●●●●●●●●●●OverviewLocking down an ASP.NET applicationASP.NET process identity security considerationsUsing Aspnet_setreg.exe to encrypt account credentials in configuration filesEnforcing machine-wide <strong>and</strong> <strong>Web</strong> application security policyAccessing resources securely from ASP.NETSecuring a <strong>Web</strong> service configurationSecuring a Forms authentication configurationSecuring ASP.NET session state <strong>and</strong> view stateSecuring a <strong>Web</strong> farmA reference table that illustrates a secure ASP.NET applicationAttributes of a secure ASP.NET applicationSecure ASP.NET <strong>Web</strong> applications rely on a fully secured network, host, <strong>and</strong> platforminfrastructure. When trust boundaries are set at each level to block the intruder, theattacker will attempt to exploit vulnerabilities in <strong>Web</strong> applications <strong>and</strong> <strong>Web</strong> servicesthat are listening on port 80. If the <strong>Web</strong> application is configured defectively, attackerscan gain access <strong>and</strong> exploit the system. As an administrator, you should review thedefault machine-level configuration <strong>and</strong> the individual application configurations toaddress <strong>and</strong> remove any vulnerable <strong>and</strong> insecure settings.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!