Re: sn.exe -Vr assembly

From: Gecko (nada_at_nada.com)
Date: 01/21/05

  • Next message: Bart: "Using a MD5 Hash with C# (.net) and Oracle"
    Date: Fri, 21 Jan 2005 16:44:38 -0600
    
    

    > Why would a user's modification of your assemblies on their own machine
    > have any effect on you?

    Well at first, it doesn't appear to have any effect since I do all data
    validation on the server so in theory, they could change that file until
    their hard drives burns and it should be no problem.

    However, I must be missing something because if tampering with local files
    was not an issue, why would anybody care to strong name their assemblies? I
    mean, if they are logged as administrator a hacker can do just about
    anything he or she wanted strong name or not CAS or no CAS, and if they are
    logged as regular users, you could install the files on GAC or on the
    ProgramFiles folder and the user would have no access to it so they can't
    touch it so why bother?

    So far I have been reading and doing very few exercise concerning Strong
    Name, CAS, DACL etc, next week I am hoping to have some time to start
    putting this knowledge to work and in the process understand this better, I
    hope thing will become clear then!!

    Thanks for all comments.


  • Next message: Bart: "Using a MD5 Hash with C# (.net) and Oracle"

    Relevant Pages

    • Re: CAS & GAC: connection?
      ... > apply with CAS and the GAC: ... assemblies will have full trust, and most assemblies in the GAC are locally ...
      (microsoft.public.dotnet.security)
    • Re: can you put a strong name assembly in a role?
      ... I hadn't fully thought out the CAS model since it ... > credentials under a similar COM+ app? ... all fully trusted assemblies will automatically pass such ... >> privileges in a SQL Server table. ...
      (microsoft.public.dotnet.security)
    • Re: Help me to undersand ???
      ... I have default settings under CAS, it means that I get Unrestricted already ... First of all when you apply security for a file/folder with with Windows ... Then for assemblies, ...
      (microsoft.public.dotnet.security)
    • RE: Could not find a part of the path - User control from within I
      ... When granting the CAS permission through strong-named codegroup, ... Are you sure whether all the assemblies used in your usercontrol(main ... evaluated as "Full Trust" permission at the client-side's .net CAS... ... usercontrol which use them reference and use them one by one and test it to ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: CAS and "My Computer" (is CAS disabled by default?)
      ... > install - totally disregards CAS? ... The default CAS does result in local ... a remotely-sourced assembly is still subject to permissions ... a full trust grant to any given assembly or set of assemblies is not ...
      (microsoft.public.dotnet.security)