11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

554 Part IV: Securing Your Network, Host, <strong>and</strong> <strong>Application</strong>●Hosting scenario. Hosting companies need to constrain applications so theycannot access each other’s resources <strong>and</strong> so that they have limited access to criticalsystem resources. To do so, you can configure all applications to run at a partialtrustlevel. For example, the medium-trust level constrains an application so that itcan only access files within its own virtual directory hierarchy <strong>and</strong> restricts accessto other types of resources. For more information, see Chapter 9, “Using CodeAccess <strong>Security</strong> with ASP.NET.” To apply a medium-trust policy for allapplications on your server, use the following configuration:

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!