EC-Council Certified Secure Programmer

EC-Council Certified Secure Programmer EC-Council Certified Secure Programmer

eccouncil.org
from eccouncil.org More from this publisher
11.07.2015 Views

Page 18• Permissions• Code Access Permissions• Identity Permissions• Role-Based Security Permissions• SkipVerification• SkipVerification Sample Code• Stack Walk• Writing Secure Class Libraries• Runtime Security Policy• Step-By-Step Configuration of Runtime Security Policies• Creating a Security Policy Deployment Package• Type Safety• Canonicalization• Access Control List Editor• Securing User Credentials and Logon Information• Obfuscation• Dotfuscator: .NET Obfuscator Tool• Administration Tool: Authorization Manager (AzMan) with ASP.Net• ASP.NET Security Architecture• Authentication and Authorization Strategies• URL Authorization• File Authorization• Windows Authentication• Forms Authentication• Passport Authentication• Custom Authentication• Implementing Custom Authentication Scheme• Security Checklist for ASP.NEThttp://www.eccouncil.orgEC-Council

o Design Considerationso Application Categories Considerations:• Auditing and Logging• Authentication–Forms• Authorization• Communication Security• Steps to Encrypt Configuration Sections in ASP.NET using DPAPI• Configuring Security with Mscorcfg.msc• Process Identity for ASP.NET• Impersonation• Impersonation Sample Code• Secure Communication• Storing Secrets• Options for Storing Secrets in ASP.NET• Web.config Vulnerabilities:o Default Error Messageo Leaving Tracing Enabled in Web-Based Applicationso Enabled Debuggingo Cookies Accessible through Client-Side Scripto Enabled Cookieless Session Stateo Enabled Cookieless Authenticationo Failure to Require SSL for Authentication Cookieso Sliding Expirationo Non-Unique Authentication Cookieo Hardcoded Credential• Securing Session and View State• Web Form Considerations• Securing Web ServicesPage 19http://www.eccouncil.orgEC-Council

Page 18• Permissions• Code Access Permissions• Identity Permissions• Role-Based Security Permissions• SkipVerification• SkipVerification Sample Code• Stack Walk• Writing <strong>Secure</strong> Class Libraries• Runtime Security Policy• Step-By-Step Configuration of Runtime Security Policies• Creating a Security Policy Deployment Package• Type Safety• Canonicalization• Access Control List Editor• Securing User Credentials and Logon Information• Obfuscation• Dotfuscator: .NET Obfuscator Tool• Administration Tool: Authorization Manager (AzMan) with ASP.Net• ASP.NET Security Architecture• Authentication and Authorization Strategies• URL Authorization• File Authorization• Windows Authentication• Forms Authentication• Passport Authentication• Custom Authentication• Implementing Custom Authentication Scheme• Security Checklist for ASP.NEThttp://www.eccouncil.org<strong>EC</strong>-<strong>Council</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!