Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Programming > ASP .Net > ASP .Net Security > Security design question

Thread Tools

Security design question

John Lee
Posts: n/a

Here is the environment related context:
================================================== =======================
Website are hosted in DMZ - subdomain created
We have our web farm (3-5 web servers) running under one NT Domain account
with least privileges.
Website all 3 level of access: anonymous, registered and verified
We will use form authentication to authenticate registered and verified user
SQL server will be used to host user authentication information and Session
All Line of business web services are hosted internally with Windows
authentication only
AzMan is used to perform access check on all public web methods
================================================== =======================
My question are:

Is this a good practice? Any obvious flaw?
What is the best way to encrypt session state because it might contain
sensitive data?
If the internal web service trust the NT domain account that hosts the web
site, it means that if someone gain access/control to the site then he could
possibly call any of the web service methods, is this correct? how to
prevent it from happening?
What is the best way to secure public access website that will
retrieve/update internal business data?

Thanks very much!

Reply With Quote
Posts: n/a
Hi John,

From the design, you may consider add some firewall between outside and
your web site, either, between your web server and Web serivce
server/database. This can help block the attcks. Here are some good
articles on ASP.NET security, you may take a look first to see they will

Securing Your ASP.NET Application and Web Services

Securing .NET Web Applications in an Intranet Environment

An Introductory Guide to Building and Deploying More Secure Sites with


Reply With Quote

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
class design/ design pattern question Bartholomew Simpson C++ 2 06-12-2007 08:51 PM
Security design question Jeremy Chapman ASP .Net Security 3 04-20-2006 04:25 PM
OO design in servlet design question dave Java 5 07-17-2004 12:58 PM
J2EE Security Design Question Ryan Pape Java 1 09-12-2003 07:40 PM
IT-Security, Security, e-security COMSOLIT Messmer Computer Support 0 09-05-2003 08:34 AM