Re: What is the best way to Invoke a java application from ASP.NET

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Scott Allen (bitmask_at_[nospam)
Date: 10/21/04


Date: Thu, 21 Oct 2004 11:09:42 -0400

Anybody accessing the web server would be able to execute the program
- but it's hard to judge the risk without knowing what the program
does, what it's input and outputs are, etc. I'd also be concerned
about the scalability of the solution - so I'd test with the number of
concurrent users you expect the site to see and make sure the process
doesn't drag the server down.

--
Scott
http://www.OdeToCode.com/blogs/scott/
On 21 Oct 2004 06:20:54 -0700, lybbert@adelphia.net (Aimee) wrote:
>I have created an ASP.NET (VB) website and need to invoke a command
>line application (a Java app) when the user submits a form.  What is
>the best method for approaching this?
>
>I've read about using the Diagnostics.Process class.  One user raised
>a concern about the security hole this approach creates (because you
>have to give the ASPNET user execute permissions).  In a dedicated
>hosting environment, what kind of risk would be raised by giving the
>ASPNET user these permissions?


Relevant Pages

  • Buffer Overrun in Talentsofts Web+ (3) (#NISR17042002B)
    ... Name: Web+ Cookie Buffer Overflow ... Attackers can run arbitrary code as SYSTEM on the web server. ... If the server is running IIS 4 and using the Web+ ... As this has limited privileges the risk is reduced. ...
    (Bugtraq)
  • RE: Should webservers, eg. IIS 6 have anti--virus installed on them?
    ... It's part risk analysis, part cost/benefit ... You either choose to accept the risk of pushing out defs ... a/v deployment set in such a way] that I can do this. ... >>If a web server is just a web server, ...
    (Focus-Microsoft)
  • Re: Windows Virus using group posters
    ... > malicious mail if he doesn't know, or can't guess, your email address. ... The excess email doesn't put me 'at risk' of anything. ... Outlook will execute code in emails, ... Eudora) the email programs do not execute code, ...
    (comp.lang.cobol)
  • Re: SP2 Security Holes
    ... > internet or e-mail attachment. ... The risk here is that it could be any ... > drag the file to the command window. ... > execute any file based on content rather than extension and ignore ...
    (microsoft.public.windowsxp.basics)
  • Re: Crystal Reports for VS 2005 Error on Print
    ... directories on your web server. ... The report previews fine, but clicking the embedded ... "HTTP 403.1 Forbidden: Execute Access Forbidden ... crTables = crDatabase.Tables; ...
    (microsoft.public.dotnet.general)