Psst! Did you know DevelopmentNow is a mobile web site design agency?

Contact us for help mobilizing your site, or to sign up for our beta Mobile Web SDK!


Archived Months
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
May 2008
June 2008


all groups > asp.net security > october 2007

How To Add User's GUID To An Account Verification E-mail
Posted by Jonathan Gill at 10/27/2007 6:37:00 PM
Hi everyone, So I have a problem that is more difficult that it might seem at first glance. created. Any help/a clever "duh" answer would be great as we've spent more than 8 hours trying to get this working. Please see the following thread for the full details: "How To Add User's GUID T...more >>

Defining Groups with AD users
Posted by GeoffreyD at 10/25/2007 10:35:54 PM
Hi I am working on an internal ap.net site and am wanting to assign permissions to users using their AD account to authenticate against, but am not wanting to setup the actual groups within AD. At the moment is it seems that my only answers are ADAM and AzMan. does anyone have any suggestio...more >>

"index out of range ..." error when querying AD?
Posted by E. Kwong at 10/24/2007 3:17:28 PM
I have a simple login form to authenticate users. A code segment looks like this: search.PropertiesToLoad.Add("cn"); search.PropertiesToLoad.Add("name"); search.PropertiesToLoad.Add("givenname"); search.PropertiesToLoad.Add("sn"); ...more >>

"index out of range ..." error when querying AD
Posted by E. Kwong at 10/24/2007 3:12:00 PM
I have a simple login form to authenticate users. A code segment looks like this: search.PropertiesToLoad.Add("cn"); search.PropertiesToLoad.Add("name"); search.PropertiesToLoad.Add("givenname"); search.PropertiesToLoad.Add("sn"); ...more >>

Windows Authentication and Anonymous Access
Posted by Competitive Dad at 10/24/2007 2:03:00 AM
I have a requirement that I need to create a website running on IIS6 that needs to be anonymous access by default with Windows once a "Sign in" button is clicked. I've pondered about this and have come up with a solution, but I just want to check it here to make sure I'm not going to get ca...more >>

Encrypted Connections Strings not safe in memory?
Posted by Rick M. at 10/22/2007 9:05:02 AM
Simply put, best practices say to: 1) Put ConnectionString info in to web.config for easier editing (and disallow the need to recompile code if settings change). 2) Encrypt the ConnectionString section using the aspnet_setreg.exe utility. This encrypts the data on the IIS/OS level disal...more >>

Access denied 403.7 client certificate
Posted by Zerro at 10/22/2007 2:40:01 AM
Hi, I'm trying ta access a webservice that requires identification by client certificate. Browsing the webservice and console testprogram works fine, but my webapplication gets a 403.7 access denied all the time. I've followed the instructions and imported the certificate with Winhttpcertc...more >>

How to test a asp connection to mysql?
Posted by David at 10/20/2007 11:22:37 PM
Have just installed mysql on to my server Does anyone know of a sample test script that will test if asp can connect to a test databse?. I just want to find out if it is working. thanks ...more >>



Form Authentication?
Posted by Sulaiman at 10/19/2007 12:26:07 AM
Please correct me if I am wrong here, When we put the username/password in the Form Authentication Web application, usually the username/password is stored in the cleartext, in the client memory space. So what happen is that in the public computer, a hacker can run a program like Winhex to r...more >>

Integrated Windows Authentication and Session Timeout.
Posted by Sulaiman at 10/18/2007 6:29:03 PM
The main idea of IWA is to have a single sign on capabilities web site and I think it is good if you have a web that cater internal people. A few questions coming out from this implementation 1) How does the C# Windows Authentication work? Does the NTLM handshake only happen in the first reque...more >>

Password shown in browser
Posted by Michael G. Schneider at 10/15/2007 12:00:00 AM
Suppose web.config contains <authentication mode="Windows"/> <identity impersonate="true" userName="XYZ" password="XYZ"/> and the password is wrong. Then if the website is opened in the browser, a message is given that shows the above section on the page. What makes this section app...more >>

ASP.NET 2.0 WindowsTokenRoleProvider Local Groups Broken
Posted by Howard Hoffman at 10/10/2007 6:33:45 PM
I've an IIS6 ASP.NET 2.0 web site (not a virtual directory, a web-site). I've configured the web-site (following directions at http://support.microsoft.com/kb/215383) in the MetaBase to allow NTLM and Negotiate access, and the site itself is using Integrated Windows Authentication and allow...more >>

Problems deploying website with membership features from XP to 2003 (take2)
Posted by Sam Samson at 10/10/2007 12:00:00 AM
greetings all, (again blasted newsreader killed my initial epic, email post numero 2) I have a dev box(XP) that I am developing an ASP.NET 2.0 application .. am trying to use membership features .. have set up my local box secured a directory dropped in an ASP:LOGIN web control added some ...more >>

FormsAuthentication.SignOut() what to do after
Posted by IfThenElse at 10/8/2007 8:33:13 PM
Hi, I am still able to navigate back to secure area even after calling FormsAuthentication.SignOut() on the logoff.aspx I read some place that I need to clear the cookie, expire it etc.. But I am not getting it right. Need examples tutorials etc.. please help. ...more >>

Sends me to my Login page even after I'm logged in
Posted by Jim at 10/8/2007 2:46:09 PM
Hi, I'm trying to setup ASP security for the first time and am having some problems. If anybody can help, I would greatlly appretiate it. I setup the aspnetdb and setup users and roles through the ASP.net configuration. I setup a Logincs.aspx page with a Login Web Control. When I go to my ...more >>

Visual Studio.Net Professional not running after installation
Posted by Alli-Balogun at 10/7/2007 8:57:01 AM
Could not get the Visual Studio.Net Professional not running smoothly. and the server 2003 was asking me for connection. above all, i could not integrate both the server and the Visual Studio.Net Professional to running after installation....more >>

Try to hack my web site!
Posted by Ivo at 10/5/2007 12:00:00 AM
I am programming forum. Tech is ASP.NET, C# and SQL Server 2005. I want to see is my site safe, have I made some security problems. Can you try to hack my site untill 10-september-2007.: http://www.search4affiliate.com/Forum.aspx Thanx ...more >>

Bad Request <OR> Illegal characters in path
Posted by nexdeveloper at 10/4/2007 1:46:01 PM
Here is my issue: 1) This is an ASP.NET 1.1 website hosted on Windows2003 Server 2) SP1 for .NET 1.1 is installed 3) I have the .gif extension mapped in IIS to the 1.1 aspnet_isapi.dll 4) I have an httphandler configured for the website: <add verb="*" path="*.gif" type="myNamespace.myHandl...more >>

Unable to encrypt some sections in web.config
Posted by Olivier MATROT at 10/4/2007 12:31:02 AM
Hello, I would like to encrypt configuration sections with "aspnet_regiis" and "-pef" option. This is working fine for most of the sections I'm interested in, for instance <appSettings> and <connectionStrings>. This is not working for the <identity> section. The tool claims that the sectio...more >>

How to get LDAP server?
Posted by william at 10/3/2007 12:29:01 PM
HI, I'm new in LDAP. I want to use LDAP server to do authentication and authorization for our .NET web applications. My question are: 1. Where can I get microsoft LDAP server(service?)? Not ADAM. 2. Can I install it on win XP? 3. Can I install multiple instance of LDAP server on one machine?...more >>

Application Flow / security issues
Posted by Justin Rich at 10/1/2007 4:05:53 PM
im having some issues with application security and i was wondering if anyone could point me in the direction of some good resources that would explain the different levels of security. the problem im currently having is im trying to make a web app that will pull a file from the client (cli...more >>


DevelopmentNow Blog