Ask a Question related to ASP.NET Security, Design and Development.
-
Chipmunk #1
Security issues relating to submitting href links and text:
I am currently developing a website (ASP.NET) which allows users to
submit a web form containing a href link in one field and descriptive text
in another field. The records will stored to varchar columns in a SQL Server
2000 database and hosted by a 3rd party ISP. The list of links will then be
made available to other users.
What general security precautions should be taken when developing a
website of this nature? Specifically, I am concerned about the possibility
of malicious SQL or ASP script insertion and it's impact on the web or
database server. I am already using client and server side validation to
restrict the description field to alpha-numeric characters, period and
spaces.
Chipmunk Guest
-
Page view issues with newly created links
I just finished creating links on each page of a 200 page document, allowing users to easily jump from section to section. When creating the links I... -
PHP - download multiple text files by submitting an htmlform
Hello, I am building a site that allows the user to download a set of text files based on user selection on HTML forms. For example, the user can... -
Security issues
http://tinyurl.com/2dlhq -- Ivan "Doomer" Carlos - Cell.: +55 (11) 8112-0666 icarlos@icarlos.net www.icarlos.net - -
href links
My site has gone from 5 pages to 50 over this year. Every page has a sidebar, which includes the title, content and link to the other page on my... -
Security Issues with ASP.Net
Hi All, Need some advice on some of the security issues in my ASP.Net application. There are certain tasks that I need to implement so need... -
Ken Schaefer #2
Re: Security issues relating to submitting href links and text:
Cross-site scripting vulnerabilities for starters...
Think about exploits that come out for Internet Explorer that rely on
carefully crafted malicious URLs. Someone could submit one of those into
your system. Alternatively, they might submit a link that grabs cookies for
your domain, and redirects them to a site of the user's choosing. Etc
Check out the OWASP website ([url]www.owasp.org[/url]) for more information on securing
web applications.
Microsoft also as a book you can download from MSDN on building secure
ASP.Net applications. Get that as well.
Cheers
Ken
"Chipmunk" <reply@newsgroup.com> wrote in message
news:exaUD3Z%23DHA.3808@TK2MSFTNGP09.phx.gbl...
: I am currently developing a website (ASP.NET) which allows users to
: submit a web form containing a href link in one field and descriptive text
: in another field. The records will stored to varchar columns in a SQL
Server
: 2000 database and hosted by a 3rd party ISP. The list of links will then
be
: made available to other users.
: What general security precautions should be taken when developing a
: website of this nature? Specifically, I am concerned about the possibility
: of malicious SQL or ASP script insertion and it's impact on the web or
: database server. I am already using client and server side validation to
: restrict the description field to alpha-numeric characters, period and
: spaces.
:
:
Ken Schaefer Guest
-
Eric Lawrence [MSFT] #3
Re: Security issues relating to submitting href links and text:
Please do not cross-post to so many newsgroups.
Regular expressions are your friends-- use them wisely. You'll want to
ensure that the data entered matches the formats you expect (easy for URLs,
harder for "descriptive text"). See [url]http://www.devx.com/vb2themax/Tip/19510[/url]
for instance.
--
Thanks,
Eric Lawrence
Program Manager
Assistance and Worldwide Services
This posting is provided "AS IS" with no warranties, and confers no rights.
"Chipmunk" <reply@newsgroup.com> wrote in message
news:exaUD3Z#DHA.3808@TK2MSFTNGP09.phx.gbl...Server> I am currently developing a website (ASP.NET) which allows users to
> submit a web form containing a href link in one field and descriptive text
> in another field. The records will stored to varchar columns in a SQLbe> 2000 database and hosted by a 3rd party ISP. The list of links will then> made available to other users.
> What general security precautions should be taken when developing a
> website of this nature? Specifically, I am concerned about the possibility
> of malicious SQL or ASP script insertion and it's impact on the web or
> database server. I am already using client and server side validation to
> restrict the description field to alpha-numeric characters, period and
> spaces.
>
>
Eric Lawrence [MSFT] Guest



Reply With Quote

