Need guidance on security setup

From: Craig - Roanoke (CraigRoanoke_at_discussions.microsoft.com)
Date: 02/03/05

  • Next message: ben: "RE: https on a developer machine"
    Date: Thu, 3 Feb 2005 12:43:02 -0800
    
    

    I'm looking at setting up new security.

    Right now the whole website is open except a few directories which use an
    application (ASP.NET). These applications are protected with FORM AUTH.

    Now...I'm thinking I would like to protect other directories that contain
    static content and some that contain non protected apps.

    I would like to have people be redirected to a login page if they haven't
    logged in.

    I currently have all my ID's and passwords in a SQL table, although I will
    be changing the passwords to a HASH system (but this won't make a
    difference). I use this table to authenticate against with the secure apps.

    How would I set this up? Also, would I be transmitting stuff in the clear
    or would it be protected?

    Thanks!


  • Next message: ben: "RE: https on a developer machine"

    Relevant Pages

    • Re: [Full-disclosure] Off topic rant to my friends
      ... I dunno if this is any worse than the many, ... went to a security conference users got insulted. ... SUSAN and BOB" were not good passwords. ... I do it to protect my company's investment. ...
      (Full-Disclosure)
    • Re: More SSH trolling
      ... > against the usage of secure passwords. ... SSH's encryption does protect effectively against ... "useless" since most attackers worldwide do not have the ability to ... standard security measures... ...
      (Fedora)
    • RE: Repost: Re: User authentication over the web (was: Secure Password in database)
      ... Subject: Repost: Re: User authentication over the web ... >> makes passwords easy to steal; ... > But we do not want to protect passwords. ...
      (SecProg)
    • US-CERT security awareness tips
      ... the US-CERT recently started offering security ... Choosing and Protecting Passwords ... what attacker cares about your ... One of the best ways to protect information or physical property is to ...
      (Security-Basics)
    • Re: autolock a cell after entering value into it
      ... >>unlock all cells in the range first. ... >>Ypu will also need to protect your VBA project so no one can see the ... > Next, if users are clever enough to look in VBA modules to find passwords, ... > the BeforeClose event handler e-mail the current workday's attendance ...
      (microsoft.public.excel.worksheet.functions)

    Loading