Account Creation and Security



Hi

I'm trying to design a web application where people can create user Ids and
passwords while signing up and then use that information to login to an
account. (I know, very basic). I just can't get my mind around how to make
this system most secure. the user id and password is verified at the time of
logging in and at that point, I would like to create something like a session
key before openning the new page. I basically don't want to start the new
page by passing regular parameters through the URL because that's very easy
to manipulate and break. Can someone give me some information about creating
a secure system like this and/or forward me some useful sources?? btw.. I'm
using, IIS as my server, ASP.Net and VB.Net.

Thanks

Farsad

.



Relevant Pages

  • Help with audit/password needs on Solaris 8
    ... consecutive unsuccessful attempts to login. ... Inactive User IDs are disabled after 45 days or deleted after the ... until at least four other passwords have been used. ... Pre-assigned or temporary passwords/PINs associated with User IDs ...
    (comp.unix.solaris)
  • Help with audit/password needs on Solaris 8
    ... consecutive unsuccessful attempts to login. ... Inactive User IDs are disabled after 45 days or deleted after the ... until at least four other passwords have been used. ... Pre-assigned or temporary passwords/PINs associated with User IDs ...
    (comp.unix.solaris)
  • Re: passwords and user ids
    ... > It seems to me the HTTP server and Servlet Womb ... > list of user ids and passwords. ... Further the SQL database has user ids ...
    (comp.lang.java.databases)
  • Should be "Page cannot be displayed" error after login
    ... "Andy E" wrote: ... They have user IDs and passwords assigned to them ... > "Page cannot be displayed" error page in their browser. ...
    (microsoft.public.sharepoint.portalserver)