11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

552 Part IV: Securing Your Network, Host, <strong>and</strong> <strong>Application</strong>With <strong>Web</strong>.config, the path is relative from the application’s virtual directory. Forexample:. . .Applying Configuration Settings to Specific FilesUse the path attribute to apply configuration settings for a specific file. For example,to apply authorization rules to the file Pagename.aspx from within <strong>Web</strong>.config, usethe following element:Applying <strong>Application</strong> Configuration Settings in Machine.configYou can also apply application-specific settings in Machine.config by using statements that specify paths to application directories. This has theadvantage of centralizing administration. For example, the following fragment showshow to enforce the use of Windows authentication <strong>and</strong> prevent the use ofimpersonation in a particular application.Locking Configuration SettingsTo prevent individual applications from overriding machine-level policyconfiguration, place settings within a element in Machine.config <strong>and</strong> setthe allowOverride=“false” attribute.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!