11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Introduction lxiiiThe Team Who Brought You This GuideThis guide was produced by the following .NET development specialists:● J.D. Meier, Microsoft, Program Manager, Prescriptive ArchitectureGuidance (PAG)● Alex Mackman, Content Master Ltd, Founding member <strong>and</strong> PrincipalTechnologist● Srinath Vasireddy, Microsoft, Developer Support Engineer, PSS●●●Michael Dunner, Microsoft, Developer Support Engineer, PSSRay Escamilla, Microsoft, Developer Support Engineer, PSSAn<strong>and</strong>ha Murukan, Satyam Computer ServicesContributors <strong>and</strong> ReviewersMany thanks to the following contributors <strong>and</strong> reviewers:●●Thanks to external reviewers: Mark Curphey, Open <strong>Web</strong> <strong>Application</strong> <strong>Security</strong>Project <strong>and</strong> Watchfire; Andy Eunson (extensive review); Anil John (code accesssecurity <strong>and</strong> hosting scenarios); Paul Hudson <strong>and</strong> Stuart Bonell, Attenda Ltd.(extensive review of the Securing series); Scott Stanfield <strong>and</strong> James Walters,Vertigo Software; Lloyd Andrew Hubbard; Matthew Levine; Lakshmi NarasimhanVyasarajan, Satyam Computer Services; Nick Smith, Senior <strong>Security</strong> Architect,American Airlines (extensive review of the Securing series); Ron Nelson; SenthilRajan Alaguvel, Infosys Technologies Limited; Roger Abell, Engineering TechnicalServices, Arizona State University; <strong>and</strong> Doug Thews.Microsoft Product Group: Michael Howard (Threat Modeling, Code Review, <strong>and</strong>Deployment Review); Matt Lyons (demystifying code access security); CaesarSamsi; Erik Olson (extensive validation <strong>and</strong> recommendations on ASP.NET);Andres De Vivanco (securing SQL Server); Riyaz Pishori (Enterprise Services);Alan Shi; Carlos Garcia Jurado Suarez; Raja Krishnaswamy, CLR DevelopmentLead; Christopher Brown; Dennis Angeline; Ivan Medvedev (code access security);Jeffrey Cooperstein (Threat Modeling); Frank Swiderski; Manish Prabhu (.NETRemoting); Michael Edwards, MSDE; Pranish Kumar, (VC++ PM); RichardWaymire (SQL <strong>Security</strong>); Sebastian Lange; Greg Singleton; Thomas Deml (IIS LeadPM); Wade Hilmo (IIS); Steven Pratschner; Willis Johnson (SQL Server); <strong>and</strong> GirishCh<strong>and</strong>er (SQL Server).

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!