Protect your .net web app                 Print      Add Favorite     Add Watch     Contact Author

Creator: host   1/1/2012 4:09:40 AM    Author: Joe Brinkman   Source: http://www.dotnetnuke.com/Resources/Blogs/EntryId/3237/Securing-Net-Web-Apps.aspx   Views: 179    0    0  
Tags:
Security Protect .net application


Posted by: Joe Brinkman
11/28/2011 6:24 AM  

informationsecurityFrom time to time I run across some great development resources on the web that are worth sharing.  The below list of blog posts by Troy Hunt is a great starting point if you want to find out about the biggest threats to the security of your websites and the techniques you can use in your development and site administration efforts to prevent such exploits.  While we take every effort to ensure that the core framework remains secure, there is still a lot of control that is left in the hands of module developers and site administrators. 

Note: There is still one more blog post coming in this series.

OWASP Top 10 for .NET developers series

  1. Injection
  2. Cross-Site Scripting (XSS)
  3. Broken Authentication and Session Management
  4. Insecure Direct Object References
  5. Cross-Site Request Forgery (CSRF)
  6. Security Misconfiguration
  7. Insecure Cryptographic Storage
  8. Failure to Restrict URL Access
  9. Insufficient Transport Layer Protection


Rating People: 0   Average Rating:     
Comment List:


  No Record 


Post your comment

Your Name: Required
Your Mail: Email is used only to display Gravatar
Your Site:
CAPTCHA image
Enter the code shown above in the box below
Comment Info:         

     DnnModule.com is build to provide quality modules and skins, Some of them are free,some not. We wish these stuffs( free or not ) can be useful to you.

    Besides that, We also provide a full range of professional services, ranging from web site build, seo, system management, administration, support, senior consultancy and security services.   We act as if your development project or network was ours, with care and respect. We are not satisfied until it works the way you want it to, and we don't silently ignore found issues as somebody else's problem.