|
|||||||||||
|
RE: Current Project Design, Comments?
From: Douglas Schlenker <Douglas.Schlenker(at)RoyalRoads.ca>
Date: Mon Feb 17 2003 - 11:08:49 EST
Douglas Schlenker
-----Original Message-----
Hi Michael,
All and all it looks great and I'll be glad to get your impressions/conclusions when you finish with the site, we also plan on developing an ASP.Net secured site and it will be great to get some UNBIASED remarks on ASP.Net secured sites :) Thanks and Best Regards.
Gal Rozov
Aladdin. Securing the Global Village.
Aladdin supports Idealist. Visit http://www.idealist.org
-----Original Message-----
I am currently on a project designing an ASP.NET-based application for a client. I would welcome any comments on my security design so far. Communication Protection Client Web Browser to Web Server: 128-bit SSL encryption Web Server to Database Server: IPSec (via Windows 2000 Server) Authentication Client to Web Server: Custom authentication against a username/password stored in Oracle DB. The database actually only stores the username, a hash of the password, and a random salt value used in the hashing process. No password is actually stored in the database. Web Server to Database Server: A single identity is used to talk to the DB server from the Web Server. These credentials are stored on the Web Server in encrypted form and are decrypted when needed (and stored in memory). The key for decryption is the password of the web account - this is all handles via Window's data protection api. Authorization Client to Web Server: Subsystems of the application are protected via custom role-based security. Each user has a "role" and if that page is not viewable by that role, they are redirected to a different page. Web Server to Database Server: The trusted identity has minimum rights to the specified tables and procedures needed to perform its duties. Pretty standard in the web world, correct? I am still trying to figure out a universal way to handle SQL injections. I garnered most of this from Microsoft's whitepaper on secure ASP.NET applications. -- Michael Loll Consultant / Pointe Technology Group, Inc. mloll@pointetech.com / www.pointetech.com work: 301-306-4400 x4441 / cell: 240-603-7372 / fax: 301-306-4421 * This email is my opinion and not that of my employer. ******************************* IMPORTANT ! ********************************** The content of this email and any attachments are confidential and intended for the named recipient(s) only. If you have received this email in error please notify the sender immediately. Do not disclose the content of this message or make copies. This email was scanned by eSafe Mail for viruses, vandals and other malicious content. **************************************************************************** **Received on Mon Feb 17 12:58:15 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:49 EDT |
||||||||||
|
|||||||||||