11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Checklist: Securing Remoting 715Sensitive DataCheck DescriptionExchange of sensitive application data is secured by using SSL, IPSec, or a customencryption sink.Exception ManagementCheck DescriptionStructured exception h<strong>and</strong>ling is used.Exception details are logged (not including private data, such as passwords).Generic error pages with st<strong>and</strong>ard, user friendly messages are returned to the client.Auditing <strong>and</strong> LoggingCheck DescriptionIf ASP.NET is used as the host, IIS auditing features are enabled.If required, a custom channel sink is used to perform logging on the client <strong>and</strong> the server.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!