Re: How to Check Roles in ServicedComponent when client is ASP.Net

From: Mary Chipman (mchip@nomail.please)
Date: 11/30/02


From: Mary Chipman <mchip@nomail.please>
Date: Sat, 30 Nov 2002 12:29:53 -0500


There's a chapter in the new "best practices" asp.net security wp that
explains this -- see
http://www.microsoft.com/downloads/release.asp?ReleaseID=44047

-- Mary
MCW Technologies
http://www.mcwtech.com

On Mon, 25 Nov 2002 17:34:09 +1100, "Cenon Del Rosario"
<cenonmin@ihug.com.au> wrote:

>Hello,
>
>I was wondering if someone can provide some info on the following issues I
>have with regards to a web application we are trying to develop. Our set up
>is as follows:
>
>1) We are developing ASP.Net pages that will instantiate ServicedComponents.
>2) Users will log on to the web application using Forms authentication.
>3) The ServicedComponents will use IsCallerInRole to check a user's
>security.
>
>Questions:
>1) How do we design the ASP.Net side so that each user process can be
>checked by the the ServicedComponent ?
>2) Do we have to do some sort of impersonation here to be able to do this ?
>
>Thanks in advance.
>
>Cenon.
>



Relevant Pages

  • Re: [Full-Disclosure] DCOM RPC exploit (dcom.c)
    ... ** The r00t of the problem is a failure to follow best practices from ... > server; security HAS to come second to that. ... > As for how many are protected - not enough, which is again a cost issue. ...
    (Full-Disclosure)
  • Re: Access Control Best Practices for shared hosting seem at odds with Web Site Starters
    ... The practical implementation of security measures is an exercise for the ... reader -- but best practices is not. ... With respect to DotNetNuke and the Community Server, yes, these are not ... > permissions because the app requires it or I use an Access database. ...
    (microsoft.public.inetserver.iis.security)
  • Re: [fw-wiz] Wireless
    ... Like every other security "problem", best practices is layered defenses. ... Strong authentication - companies like netmotion, columbitech, funk have ... >> spoofing, wandering unauthorized users, etc. to prevent access to all ...
    (Firewall-Wizards)
  • RE: Microsoft technologies. By default, non-HIPAA compliant?
    ... Anything But Microsoft wrote: ... > security practices are a federally mandated requirement. ... Customer service reps may need web access to look up local doctor's ...
    (Bugtraq)
  • [Full-Disclosure] Re: Where to start
    ... If you're not working within the systems or network security field, ... on this list and a similar number will agree on which practices are "best". ... some worthwhile efforts at centralising information, such as CERT, ... of the many information sources. ...
    (Full-Disclosure)