Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: Prevent security bypass

From: Adam <a.bardsley(at)lancaster.ac.uk>
Date: Wed Feb 05 2003 - 04:57:02 EST

It depends how secure you want it as a lot of people have said but I would personally go for what you suggested as bar the v.expensive suggestions or the ones relying on being on the same NT network you arent going to get anything very secure. We have a secuirty script called on each secure page. The overhead doesnt seem that bad tbh.

Adam

-----Original Message-----
From: Chris Neil [mailto:Chris.Neil@abs-ltd.com] Sent: 04 February 2003 17:00
To: 'webappsec@securityfocus.com'
Subject: Prevent security bypass

I am new to this mailing list and so hope this conforms to the guidelines as I read them.

How do people address the issue of non-authenticated users requesting html pages directly from a site without logging in?

FYI. This is an IIS server. Our asp pages check the user is logged in, but with html pages we cannot.
My only idea so far is to convert all our html pages to asp. Is there anything less drastic?

Chris Neil
  Security Officer
  Chris.Neil@abs-ltd.com



ABS
  Tel: +44 (0) 1993 771221
  Fax: +44 (0) 1993 775081
Received on Wed Feb 5 07:07:33 2003
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:48 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library