Archived Months
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008


all groups > asp.net security > september 2006

Filter by week: 1 2 3 4 5

Authentication question
Posted by Griff at 9/29/2006 3:42:23 PM
We have (will have) a business-2-business eCommerce system. This means that the end users are grouped together by the companies that employ them. As part of the authentication screen, I'd like the following 3 fields to be completed as part of the log-on process: 1 - Your company name 2 -...more >>

Page.User object
Posted by PaulB at 9/29/2006 11:56:02 AM
We are currently developing a corporate intranet app using ASP.Net 2.0 app and wish to use Windows Integrated Security. I have developed a small test app that excercises the capabilities of using Windows authentication and I have two questions. First, we have a requirement that our app be ...more >>

Programmatically enable trace debug for a page
Posted by Steve Lynch at 9/29/2006 9:56:05 AM
Is there a way to enable the trace output programmatically? For example in the web.config under I have: <trace enabled="true" localOnly="true" pageOutput="true" /> but then I would like the code to decide at runtime (by a variable in the URL query string or something) if debug tracing...more >>

Cookieless Sessions (Sessions Without Cookies) and Security
Posted by scottymo at 9/29/2006 9:51:31 AM
My research to this point indicates that cookieless sessions have two main drawbacks: 1.) Absolute paths cannot be used without a workaround for the session id storage in the URL. 2.) A security hole is opened due to the visibility of the session id in the URL. Are there any other draw bac...more >>

User Authentication Thru LDAP MS Active Directory
Posted by Thana at 9/29/2006 12:57:08 AM
Hi , I am creating a user login page using ASP.NET 2.0 in C# to authenticate users thru LDAP MS Active Directory. Can anyone provide a sample in C# code for the user authentication ?. Thanks !. ...more >>

ASP.NET 2.0 site accessing Samba 3 shares
Posted by Michael D. Ober at 9/28/2006 3:05:57 PM
I have an ASP.NET 2.0 base site that needs to access files on Snap Appliance's Guardian OS 4.2, which is running SAMBA 3.x which is a domain member on the network. How do I get our web-server, which is a DC, to retrieve files on the Snap server? Thanks, Mike Ober. ...more >>

WindowsPrincipal m_roles, m_rolesTable, m_rolesLoaded question
Posted by costasz NO[at]SPAM gmail.com at 9/28/2006 2:14:12 PM
We have these ASP.Net 1.1 apps that use ADS authentication. There was a requirement to load ALL the roles for a particular user. We had used reflection to get to the Principal's m_roles field to get them. Now, we're running in ASP.Net 2.0 and I see that m_roles is null, m_rolesTable is null and ...more >>

authentication ticket expiring too soon
Posted by bmjnine NO[at]SPAM hotmail.com at 9/27/2006 3:54:49 PM
Hi, I am trying set up my site so that once a user logs in, they stay logged in for 72 hours unless they close their browser. I have the following in place: (web.config) ----------------- <system.web> <sessionState timeout="4320" /> <httpRuntime maxRequestLength="102400" executio...more >>



haiii..help me for the page expire
Posted by anil at 9/26/2006 11:40:22 PM
haiii... first i have created a login page ..i had loged in with the existing username & password.. after linking to several pages with that user name...i had signout the account.... & returned to my login page...but here my problem araised .... being in the login page ..i have clic...more >>

ASP.NET and directory security
Posted by quintesv via DotNetMonster.com at 9/26/2006 9:36:31 AM
Hi all, I come from a win forms background, and am building a web site that needs to interface to a FOXPRO database (DBF files). My problem is as follows: I have created a virtual directory on the same machine as where the DBF files are located. I have created a share for the DBF files, and...more >>

Help - Can I reuse existing session ID from email link?
Posted by Nanker at 9/26/2006 9:15:24 AM
Our existing ASP.NET web application does store a session ID in the cookies (ASP.Net_SessionID) for a logged in user. A new requirement has been stated that we need to be able to send a customer an email with a link to a specific page in the application, and if the user clicks on the email link ...more >>

Managing user rights
Posted by Angel Romero at 9/25/2006 11:42:07 AM
Hi everybody Does anybody have examples (source code or links) of best practices for managing user rights, roles, etc using SQL Server? Thanks in advance ...more >>

When are the FormsAuthentication class' configuration settings read?
Posted by matt at 9/25/2006 3:52:48 AM
Hi, I'm writing a HttpModule which is going to require certain settings in the FormsAuthentication configuration (for example, I need to ensure enableCrossAppRedirects = true). Now my best effort so far has been to run through the configuration settings I require and raise exceptions if the...more >>

Supporting multiple custom RoleProvider versions
Posted by Chris Cichocki at 9/22/2006 11:40:02 AM
All of the configurations I've seen for the role provider specify a simple (weak) type name. What if I had multiple custom role provider implementations in the GAC and wanted to specify an exact version? I've tried putting the fully qualified (strong) name into the "type" attribute but it ...more >>

Changing Active Directory Password from ASP.Net Web Page
Posted by Chris Bingham at 9/22/2006 9:28:02 AM
Hi, I’m trying to create a simple ASP.Net 2 web page to allow users to alter their Active Directory passwords, but I can’t seem to get it working and I was hoping someone might be able to help me please? Basically, the situation I’m in is this. I have a small, air-gapped network for ...more >>

ASP.Net site from network share
Posted by Navnit at 9/22/2006 4:45:01 AM
Hello, I want to create a website in IIS which has its ApplicationPath or Virtual Directory from a network share. Its a ASP.Net 2.0 website. I've the site percompiled (One Assembly Per Page). When I try to do the above I get a "Code Access Security" error, which is justified since I am ...more >>

Re-login if authenticated after session has expired
Posted by peter NO[at]SPAM cooperzone.net at 9/21/2006 6:14:08 PM
Hi, I have the requirement to allow users to log in just once per day even if their session has expired. Sessions are set to 30 minutes, and I'm using forms authentication. I had this working nicely under .NET 1.1. Once authenticated, I wrote a persistent authentication cookie that timed out ...more >>

Is the membership & role management right for me? [ASP.NET 2.0]
Posted by Griff at 9/21/2006 3:15:19 PM
Hi We are re-writing an old classic ASP system and I've been doing some reading up of the new security features in ASP.NET and I'm not sure that they're suitable for me...but perhaps I've got completely the wrong end of a the stick. I'd be grateful of some guidance here. To describe the...more >>

Windows + Custom Security hybrid??
Posted by Chris Cichocki at 9/20/2006 1:37:01 PM
We have an ASP.Net 1.0 application that has a proprietary database with role information in it. The site is configured to use Windows authentication, then it uses your Windows ID as the key to load your role information and store it in a custom object along with some other user attributes. N...more >>

Access Denied Error comes when i send FAX
Posted by Patel Mitesh at 9/20/2006 4:43:01 AM
Hi all, I have made one FAX application using FAXCOMLib on Windows 2003. Dim FS As New FAXCOMLib.FaxServer Dim FD As FAXCOMLib.FaxDoc FS.Connect(ServerToConnect.Trim()) FD = FS.CreateDocument("C:\FAX.DOC") FD.FileName = C:\FAX.DOC ...more >>

asp.net 2.0 in Win2k crossing domains.
Posted by Pierre at 9/19/2006 5:55:25 PM
Hello. I've created a web app in asp.net 2.0 to be able to copy files accross DOMAINS. Server A, the source server is in Domain 1 and Server B the destination server is in Domain 2. An ipsec tunnel was tested via a drived mapped on Server A to Server B. Mapping the drive on server A prompte...more >>

It is an error to use a section allowDefinition='MachineToApplicat
Posted by Neal Miller at 9/19/2006 2:45:02 PM
Hi, I'm getting the following error: "It is an error to use a section registered as allowDefinition='MachineToApplication' beyond application level. This error can be caused by a virtual directory not being configured as an application in IIS." I have researched this issue a lot, and ca...more >>

Pure LDAP Authentication using vb.net
Posted by Chris Davoli at 9/19/2006 7:21:02 AM
I need a vb.net sample code that authenticates users against a repository that supports LDAP. The resposiitory is NOT Active Directory. After authentication it would be great if the sample code also retrieves group membership using LDAP. -- Chris Davoli ...more >>

Different results between declarative and imperative security
Posted by Karin at 9/19/2006 12:00:00 AM
Hi, Can anyone tell me why I get two different results with the following 2 ways of checking to see if I'm in the Administrators group? This is in a Windows form in C#: If I comment out the first line (the PrincipalPermissionAttribute line), then I get the message that I am an Administrato...more >>

ASP 2.0, C#, LDAP Login, and Forms impersonation?
Posted by Karl at 9/18/2006 5:42:00 PM
Will a forms authentication allow me to impersonate a user? I am working on an application that will run on a kiosk, and allow a user to login and view their homedirectory. I have a form with the new login control which works great. I get logged in, and find the user's homedirectory. I ...more >>

Authentication problem
Posted by Dave Slinn at 9/18/2006 4:30:51 PM
I have come across a very weird situation. I made a slight modification to our authentication process to allow a single deployed website to authenticate a user with either forms authentication (if coming from an unknown network, such as the internet) or windows authentication (if coming fro...more >>

How to get the USERID
Posted by Doug Batchelor at 9/17/2006 6:15:05 PM
I am using the ASP.NET membership stuff and have succesfully implemented it on my site. However, I would now like to be able to get the UserId which is stored for registered users in the aspnet_users table in ASPNETDB.MDF. The reason is that I would like to include this value for users who ins...more >>

LDAP Auth Problem - COM interop
Posted by Chris Davoli at 9/16/2006 6:14:02 AM
Environment: Win XP, VS2003, Active Directory I'm trying to use LDAP to authenticate users. I used article http://support.microsoft.com/?id=326340 How to authenticate against the Active Directory by using forms authentication and Visual Basic .NET, but am having a COM interop error when I do...more >>

ASP.NET 2.0 Security - Guidance needed
Posted by Prem Kumar at 9/15/2006 9:28:01 PM
Hi I am using the security model of ASP.NET 2.0, am trying to do Forms authentication in my application. I am creating the roles and the users necessary for the application using the in-built provider model. Now the question is 1. how to design my application, to make sure that certai...more >>

Profile Data Inter-Application Access
Posted by wolfkden at 9/15/2006 7:36:01 PM
I have developed a profile database with a SQL provider using ASP.Net 2.0 profile programming and utilities in an IIS Web application. From other Web applications on the same web server I cannot access this data through profile common while using the same web.config profile settings and class ...more >>

Authorization_Request event in Global.asax
Posted by Chris Davoli at 9/15/2006 6:36:02 PM
If I mix classic asp pages into a .Net ptoject, and I need the Authorization_request event in the gloabal.asax to fire (implementing LDAP security), will the Authorization_request event fire for the classic ASP page? -- Chris Davoli ...more >>

LDAP Auth Problem - COM interop
Posted by Chris Davoli at 9/15/2006 1:02:02 PM
Joe, below is the error. Is there anything you can think of? Also, I am going to buy the book this weekend. Can I download these samples from chapter 12? What is this .Net 2.0 ActiveDirectoryMembershipProvider? Where can I find some info on it? Chris Server Error in '/FormsAuth...more >>

Custom Membership Provider with multi databases
Posted by tao lin at 9/15/2006 12:00:00 AM
Hi, all I have tested the Sample Access Providers from Provider Toolkit and get some feeling how to write a Custom Membership Provider. But now in my own asp.net app I cannot make my Custom Membership Provider working with multi databases. My aps.net web site using querystring such as htt...more >>

LDAP Auth Problem - COM interop
Posted by Chris Davoli at 9/14/2006 2:47:01 PM
Environment: Win XP, VS2003, Active Directory I'm trying to use LDAP to authenticate users. I used article http://support.microsoft.com/?id=326340 How to authenticate against the Active Directory by using forms authentication and Visual Basic .NET, but am having a COM interop error when I do...more >>

How to install ASP.NET Web Application on SBS2003 server
Posted by Tony Girgenti at 9/14/2006 12:03:40 PM
Hello. I developed and tested a web application using VS.NET 2003, VB, .NET Framework 1.1.4322, ASP.NET 1.1.4322 and IIS5.1. It uses a web form. When i go to client site, if they have their own SBS2003 SP1 server with IIS6.0 installed on it and their company web site is accessed using Sh...more >>

Having the darndest time trying to install and run at client
Posted by Tony Girgenti at 9/14/2006 11:56:50 AM
Hello. I developed and tested a web application using VS.NET 2003, VB, .NET Framework 1.1.4322, ASP.NET 1.1.4322 and IIS5.1. It uses a web form. I'm having the darndest time trying to make this program install and run at client site. Not so much install anymore, but there are still some i...more >>

Setting impersonation values programmatically
Posted by itmanager at 9/14/2006 10:30:02 AM
We have an ASP.NET application (v1.1) that requires some impersonation in order to access network shares. We have the following setting in the web.config file: <identity impersonate="true" /> This allows the application to access network shares if the web site is using Basic or Integrat...more >>

Reading Mail attachments in asp.net
Posted by sweetyshiny23 NO[at]SPAM yahoo.co.in at 9/13/2006 8:18:35 AM
Hi, I have a requirement wherein the users would send mails with excel attachements to a particular group id. I have to open the files read the data and store the data in the database. The mail server is an exchange server. Any pointers on how this could be implemented or code snippets would...more >>

Forms Authentication against ADAM
Posted by gely at 9/12/2006 8:34:02 AM
Using .NET 2.0 I need to be able to authenticate against an instance of ADAM from an internet browser. At the moment, I am assuming forms based authentication. Here is what I have so far: ADAM is installed on my local workstation (XP Pro). The web site is on a server (Win2K3). Using ...more >>

What LDAP Ports thru DMZ
Posted by Chris Davoli at 9/11/2006 1:01:01 PM
I am going to use LDAP to look up userids on an active directory server. The LDAP server is on the outside in the DMZ. The Active Directory server is on the inside, so holes need to be poked into the firewall. My question is, what ports need to be poked into the firewall so I can read active d...more >>

ActiveDirectoryMembershipProvider "Access is denied."
Posted by Andy Klare at 9/11/2006 11:22:51 AM
We are tyring to get the ASP.NET 2.0 ActiveDirectoryMembershipProvider to work so we can use the built in Login Control but we are getting "Access is denied.". Our user in our provider config was made an Account Operator so we believe it should have the appropriate permissions. It also appea...more >>

importing public key from X509 certificate
Posted by kodurradhika NO[at]SPAM gmail.com at 9/10/2006 7:56:55 PM
Hello, I wanted some help for "How to import public key from X509 certificate and encrypt it with an XML token". X509 class in ASP.NET 1.1 isnt much help or maybe i am missing something here . I wanted to know if someone has details about how to go about this.I m planning to use RSA crypyto s...more >>

asp to asp.net conversion
Posted by John at 9/10/2006 3:23:21 PM
Hi I have a pure asp app which I need to integrate into an asp.net app in terms of the asp.net membership/roles/login that asp.net app uses. I understand there is no way for a pure asp app to share session etc. with asp.net i.e. it can't work with asp.net membership/login. In which case is ...more >>

FormsAuthentication.GetRedirectUrl()
Posted by Alex Maghen at 9/10/2006 9:20:02 AM
The "FormsAuthentication.GetRedirectUrl()" function takes two parameters: - username - createPersistentCookie I don't know *why* the function needs these parameters to tell me what the original URL had been that had been requested before the user was redirected to the Login page. Is the...more >>

ASP.NET Security
Posted by James Wong at 9/7/2006 6:20:46 PM
Hi, My local computer is Windows XP, and other server is Windows Server 2003. I use VB.Net 2005 to develop some web service program, this program will connect to this server. The local computer and the server is using same domain. (e.g. MyDomain) By the way, I use the debug mode (dynamic p...more >>

Security Exception when accessing the registry
Posted by Jason at 9/6/2006 12:00:00 AM
Hello everyone, I've got a security issue that I can't find a solution to and was hoping someone could point me in the right direction. I'm trying to open a registry key for read only access with Registry.LocalMachine.OpenSubKey but I'm getting this security exception "The application attem...more >>

SSL ADAM and XP
Posted by Noremac at 9/5/2006 3:11:01 PM
I am going around in circles. Sorry for posting a question that may already be answered. I want to use the ADAM Membership Provider on my development Windows XP machine using VS2005. I have ADAM working on my local computer. I got it working through the ASP.NET 2.0 RBAC article. I se...more >>

Mixed Mode (Forms & Windows) Authentication
Posted by crpietschmann at 9/5/2006 9:48:02 AM
I have an ASP.NET application that is used remotely (over the internet) by our clients that uses Forms authentication and the usernames/passwords are stored in the database. I need to integrate Windows authentication with the existing Forms authentication so that our employees (on the intranet...more >>

About string parameters to stored procedure
Posted by Owen Wong at 9/3/2006 11:36:06 PM
Hi, I wrote a stored procedure to check user's name (vartype: chr) and password (chr, too). Do I have to check whether there is an apostrophe ("'") in the name string and password string? I tried to put some "'"s in the name string and didn't replace them with double "'", but it seemed you can n...more >>

IIS Authentication vs. WindowsIdentity
Posted by Steve Lynch at 9/1/2006 6:05:30 PM
Why do I get different results from WindowsIdentity.GetCurrent().Name than what is defined for authentication on the IIS virtual directory? For example in IIS6 I have the VD set to Windows Integrated Authentication only, yet the property WindowsIdentity.GetCurrent().Name or WindowsIdentity.G...more >>


DevelopmentNow Blog