Re: Exception with Child AppDomain



Yes, I agree there is a security issue.

This is not an issue where a page can be browsed by one user and not
by another. The AppDomain work occurs in the Session_Start event,
presumably before any page is instanced. It appears to me that an
unknown user account does not have permissions to load or Reflect over
the external DLL for Remoting.

I am unable to properly debug this because if I am in the VS.NET 2003
debugger (where I develop as a local Administrator), the problem does
not occur. It occurs only when the app content is xcopy-deployed to
the remote web server and the site is then accessed by an unprivileged
user. I set up the web app to send an email when an Exception is
thrown, that is the only reason I have the info I previously posted.

The ACLs on the bin directory (where the external DLL is located)
allow "R"ead for the local group that can otherwise access the site.

Do I need to create custom Evidence so "everyone" can load the
Assembly?


On Fri, 16 Dec 2005 08:17:42 GMT, lukezhan@xxxxxxxxxxxxxxxxxxxx
([MSFT]) wrote:

>>From your description, it seems to be a security issue. Your ASP.NET
>application will use the current user's acount to load the app domain. To
>confirm this, you can logon on as a local administrator, and browse to the
>ASP.NET web page, what will be the result?
>
>Luke

.



Relevant Pages

  • Re: Security Exception when deploying a VB.NET 2003 Solution
    ... It runs fine on any workstation. ... folder 2 levels up from the BIN folder where the application resides. ... Microsoft .NET security errors upon trying to start the Executable. ... I bet the workstaion is WinXP and your app is trying to write data( ...
    (microsoft.public.vsnet.general)
  • Re: Access 2002 Security on multiple workstations
    ... > I am trying to learn on the fly about Access Security for an app we ... I realize Access security is an advanced subject ... > I also have two Client PC's: Client1 and Client2 who use MyApp. ... You need to start over with the proper security FAQ documents and follow all ...
    (comp.databases.ms-access)
  • WM5 Security Queries
    ... the Security model in WM5. ... in the past but my app has been designed mainly for Pocket PCs and Pocket PC ... I have a Dell Axim X51v Pocket PC with WM5 and have been doing some testing ... While I am gradually coming to grips with the Security model, ...
    (microsoft.public.dotnet.framework.compactframework)
  • Re: Sygate Free PFW
    ... security holes won't be fixed. ... switch to the windows XP SP2 firewall? ... Windows firewall does not inform user when an apps tries to connect ... This arrives, of course, when app is installed in a session where user has ...
    (comp.security.firewalls)
  • Re: lets vote for better security
    ... Liberals and security professionals who occassionally wear a black hat. ... Then MSFT started disabling things by default and a lot of the community ... Since when is an app responsible for the ... :>: default installation and be disable-able by Group Policy. ...
    (microsoft.public.security)