Re: web.config location

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Curt_C [MVP] (software_AT_darkfalz.com)
Date: 05/12/04


Date: Wed, 12 May 2004 13:33:51 -0500

we encrypt the values in the web.config, as they pertain to connection
strings and such.
Just use an encryption class and decrypt when using them. Much better
feeling of security too :}

-- 
Curt Christianson
Owner/Lead Developer, DF-Software
Site: http://www.Darkfalz.com
Blog: http://blog.Darkfalz.com
"mike" <someone@somewhere.com> wrote in message
news:%23Z35kxEOEHA.2244@tk2msftngp13.phx.gbl...
> I agree - I see the web.config as a safe mechanism for storing data - I
> would feel safer if registry keys are used for configuration strings and
> maybe a few other things.  But if there is a guarantee that the config
> cannot be served and it has file level security against it being viewed by
> just anyone, I dont think that you can offer any more security - I believe
> the security policy for gov't apps just has not evolved to the .NET
> application and we are struggling with that transition period....
>
>
> "Curt_C [MVP]" <software_AT_darkfalz.com> wrote in message
> news:udvJTlEOEHA.1276@TK2MSFTNGP11.phx.gbl...
> > but in that rationale NOTHING is secure. Since the web.config is text it
> has
> > a security risk, but the thing is they would need file level access to
the
> > server, which if they have the contents of the web.config are irrelevant
> > anyway since they can already do/see what they want reguardless of where
> it
> > is.
> >
> > -- 
> > Curt Christianson
> > Owner/Lead Developer, DF-Software
> > Site: http://www.Darkfalz.com
> > Blog: http://blog.Darkfalz.com
> >
> >
> > "mike" <someone@somewhere.com> wrote in message
> > news:uKQdzMEOEHA.2716@tk2msftngp13.phx.gbl...
> > > well that appears to be something that we will have to explore -
> petition
> > to
> > > have it be allowed, but that would only get us for the specific .NET
> > > functionality.  Application stuff would still need to be sent off to
> > another
> > > config file...
> > >
> > > I would think they would have to know since they will be hosting this
> > site.
> > > BUT I just think they are being difficult right now...
> > >
> > > the other thing is that in certain places, Microsoft has said that the
> > > web.config is not enitirely secure because connection strings,
assembly
> > > information and such can be put in there.  As soon as a gov't agency
> sees
> > > "not secure" they say no, no matter what the reasoning or information
is
> > > behind that claim.
> > >
> > >
> > > "William F. Robertson, Jr." <wfrobertson@kpmg.com> wrote in message
> > > news:OMpr%23AEOEHA.484@TK2MSFTNGP10.phx.gbl...
> > > > Does the government agency understand that it is hard coded into IIS
> not
> > > to
> > > > server web.config files, ever, never, forever?
> > > >
> > > > bill
> > > >
> > > > (or atleast that is the tout by Microsoft)
> > > >
> > > > "mike" <someone@somewhere.com> wrote in message
> > > > news:O%2385tgDOEHA.3832@TK2MSFTNGP10.phx.gbl...
> > > > > Part of the clients requirement is that all config files must be
> > located
> > > > > outside of the web directory.
> > > > >
> > > > > DoD and government orgs seems to not like configuration files
> anywhere
> > > > near
> > > > > the virtual directory for security reasons.
> > > > >
> > > > > you would have thought that MS would have allowed you to specify a
> > path
> > > to
> > > > > where that is....
> > > > >
> > > > > I am at a loss as to what to do now...  I have a lot of things
that
> > use
> > > > the
> > > > > web.config.
> > > > >
> > > > > "Curt_C [MVP]" <software_AT_darkfalz.com> wrote in message
> > > > > news:e8fM%23cDOEHA.620@TK2MSFTNGP10.phx.gbl...
> > > > > > no.
> > > > > > it MUST be in the root of the site/vd.
> > > > > > You can have more of them in subsequent folders to override
> settings
> > > > > though.
> > > > > > Why though? why move it out of the site? It's not accessible
from
> > the
> > > > > > outside
> > > > > >
> > > > > > -- 
> > > > > > Curt Christianson
> > > > > > Owner/Lead Developer, DF-Software
> > > > > > Site: http://www.Darkfalz.com
> > > > > > Blog: http://blog.Darkfalz.com
> > > > > >
> > > > > >
> > > > > > "mike" <someone@somewhere.com> wrote in message
> > > > > > news:ujqlaYDOEHA.3380@TK2MSFTNGP11.phx.gbl...
> > > > > > > Is it possible to move the web.config out of the application
> > folder?
> > > > I
> > > > > > > would like it off somewhere out of the web directory
> > > > > > >
> > > > > > >
> > > > > >
> > > > > >
> > > > >
> > > > >
> > > >
> > > >
> > >
> > >
> >
> >
>
>


Relevant Pages

  • [NEWS] eSeSIX Thintune Thin Client Multiple Vulnerabilities
    ... Get your security news from a reliable source. ... All Linux-based Thintune models with firmware version 2.4.38 and prior ... REMOTE ROOT SHELL / BACKDOOR ... ica con_0_10 - password for first ICA connection ...
    (Securiteam)
  • Re: [Full-disclosure] [W3af-develop] [TOOL] w3af 1.0-stable released!
    ... Congrats Andres and team! ... Moved away from handling URLs as strings into a url_object model. ... Just download and enjoy our latest improvements! ... Director of Web Security at Rapid7 LLC ...
    (Full-Disclosure)
  • Re: Please, dont kill my WiFi!
    ... potentially bypassing whatever security is at the periphery of the company ... wants to block a connection, it does notify me. ... status suddenly changes from Connected to "Driver not loaded". ... user to choose to run that email attachment or allow that ActiveX control ...
    (microsoft.public.pocketpc.activesync)
  • Re: Questions when using https://servername.local/remote
    ... I am now at home trying to access the office server. ... "Create Remote Connection Disk Wizard" I tried that and it does not work. ... or security parameters may not be configured properly ... When i try the public IP address of the server, i get into the Zywall10 ...
    (microsoft.public.windows.server.sbs)
  • Re: Crazy humanity: war against crimes against humanity and racism - or racist monopoly
    ... All I did is portray I am a hacker, ... As I approached this sect in Hong Kong, three times, they closed ... If your security people can't protect this place from me, ... When I left an old connection alive for ...
    (sci.astro)