Here are some reading about ASP.NET security.





The first one is a MUST READ....


> How bad is it to switch the user in the machine.config
> file from "machine" to "SYSTEM"? We were able to overcome
> insufficient security for ASPNET id via this method. We
> resorted to this after giving ASPNET administrator rights
> on the box did not resolve the dreaded Insufficient
> Access .NET error.
> Please share your thoughts on this.
> Thanks.