Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Programming > ASP .Net > ASP .Net Security > feedback please on asp.net app security scenario

Reply
Thread Tools

feedback please on asp.net app security scenario

 
 
Vadim
Guest
Posts: n/a
 
      09-27-2007
Hi,

I am wondering if somebody has any opinion if something is wrong with the
described below scenarion, can be improved, etc....
I think is scenario is very good.

Our asp.net app (connects to SQL Server) is installed at a client's site
using from my point of view the most standard way of security configuration:
IIS is configured for windows authentication with Impersonation=True, IIs
machine is installed in DMZ and connects inside firewall to AD and sql
server.
SQL server is also configured to use windows authentication and user
credentials obviously are propagated from IIS.
I heard complains about this scenarion that if a hacker breaks into IIS
machine they can go directly to sql server inside firewall.
Or maybe there are also other threats using this scenario.

Thank you,

Vadim


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Feedback from feedback on MCP questions Matt Adamson Microsoft Certification 0 04-27-2009 11:13 AM
Asp.net Header file scenario please ... (compilation err) Annie ASP .Net 2 09-08-2005 03:54 AM
Please please please help this guy with his open source java app casioculture@gmail.com Java 4 05-05-2005 08:24 AM
Best way to implement security scenario Alex Ayzin ASP .Net Security 3 11-23-2004 11:09 AM
Please help - Simple scenario of using ASP.Net Data Grid control Belinda ASP .Net Datagrid Control 2 06-22-2004 09:36 PM



Advertisments