RE: Web Service Security

From: [MSFT] (lukezhan_at_online.microsoft.com)
Date: 02/10/04


Date: Tue, 10 Feb 2004 08:51:06 GMT

Hi Steve,

Thank you for using the community. From the description and the code, I
found you have consider a lot for the security. The security of .NET Web
serivce rely on IIS, for example, windows authentication, SSL and IP
restrict. We can assume IIS is safe enough to a web serivce. I saw you have
a method print_authenticate in the web service, and it will valid the the
user from database. If it is a SQL server, you may consider following ways
for security:

1. Set the Seb serivce running under special account and only this account
has permisison to build a connection to the database.
2. Use IPSec to provide secure communication between the web server and
database server.
3. Add a firewall between web server and database server.

Luke
Microsoft Online Support

Get Secure! www.microsoft.com/security
(This posting is provided "AS IS", with no warranties, and confers no
rights.)



Relevant Pages

  • RE: Web Service Security
    ... Thank you for using the community. ... The security of .NET Web ... If it is a SQL server, ... Add a firewall between web server and database server. ...
    (microsoft.public.dotnet.framework.aspnet.webservices)
  • Re: SQL Server problem
    ... > Database server is Microsoft SQL-Server 2000, running on Windows Server ... > the security model on Windows 2003 server, so this is just a guess. ...
    (microsoft.public.dotnet.framework.adonet)
  • security-basics Digest of: get.123_145
    ... VPN to ASP a security risk? ... Re: Multiple IPSec tunnels? ... Subject: Security NT Server ... VPN to ASP a security risk? ...
    (Security-Basics)
  • << SBS News of the week - Sept 26 >>
    ... And he points to the info you need to put the file on the server in the ... at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... by the firewall at risk. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: << SBS News of the week - Sept 26 >>
    ... > And he points to the info you need to put the file on the server in the ... > at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... An attacker can exploit these flaws in tandem via specially ...
    (microsoft.public.backoffice.smallbiz2000)

Quantcast