Re: security considertations in deploying asp.net web apps

From: Eliyahu Goldin (removemeegoldin_at_monarchmed.com)
Date: 05/13/04


Date: Thu, 13 May 2004 15:00:34 +0200

http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=055FF772-97FE-41B8-A58C-BF9C6593F25E

Eliyahu

"Andy Fish" <ajfish@blueyonder.co.uk> wrote in message
news:YuHoc.2456$V51.20196581@news-text.cableinet.net...
> Hi,
>
> I am about to deploy an asp.net web app which will consist of a web server
> in the DMZ invoking web services hosted inside the corporate firewall.
Both
> will be hosted on IIS 5 or 6 using windows 2000 or 2003 server
>
> I am well versed in the general security considerations for this type of
> architecture but I was wondering if there are any good books or papers
with
> guidelines specifically for asp.net.
>
> I'm interested in any specific configuration options or relevant APIs
> relating to things like preventing DOS attacks, parameter validation,
> reverse proxying of SOAP messages etc etc
>
> Andy
>
>



Relevant Pages

  • security considertations in deploying asp.net web apps
    ... I am about to deploy an asp.net web app which will consist of a web server ... in the DMZ invoking web services hosted inside the corporate firewall. ...
    (microsoft.public.dotnet.framework.aspnet)
  • aspnet._wp.exe could not be started
    ... I'm attempting to use a web app that has been set up by a third party ... request failure can be found in the application event log of the web server. ... This error can be caused when the worker process account has ... .NET Framework is correctly installed and that the ACLs on the installation ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Need to write my first web application - scratching head
    ... If you write this as a web app, you'll need a web server. ... from PHP you have only partial control over how the page ... And I did suspect that the printing requirement and the single-machine ...
    (comp.lang.php)
  • Re: small data needed - suggestions?
    ... Since this is a web app...then the web server talking to an ... obituaries, etc... ... My ISP only allows me a certain # of SQL Server dbs. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Lisp user group culture
    ... pretty decent job interfacing with databases. ... The web server will handle encryption of traffic via SSL, but I need to encrypt data in the database, so a robust library for handling AES, SHA and other acronyms would be great. ... web app, ...
    (comp.lang.lisp)