ASP Security Issue
From: Amit (avmit702_at_hotmail.com)
Date: 09/29/04
- Next message: Mary Bray: "Re: Granting login and access privileges to LocalSystem"
- Previous message: Hari Prasad: "RE: xp_cmdshell"
- In reply to: S Shulman: "ASP Security Issue"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Wed, 29 Sep 2004 01:57:20 -0700
Use windows authentication of ASp and sql server 's SSPI
to get in to the database and then you can even opt for
the impersonation ... also in that case get the username
and password from the registry ;) ... i know i replied in
abstraction .... hope you can understand what i
mean .......
well as far as the user can download the actual file the
answer is no ... but a hacker can offcourse do so...
>-----Original Message-----
>Hi All
>
>I wonder whether it is safe to store the database
username and password in a
>ASP page.
>Is there any chance that a user can down load the actual
file?
>
>Thank you,
>Shmuel
>
>
>.
>
- Next message: Mary Bray: "Re: Granting login and access privileges to LocalSystem"
- Previous message: Hari Prasad: "RE: xp_cmdshell"
- In reply to: S Shulman: "ASP Security Issue"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|