𝔖 Scriptorium
✦   LIBER   ✦

πŸ“

.NET Framework Security

✍ Scribed by Brian A. LaMacchia, Sebastian Lange, Matthew Lyons, Rudi Martin, Kevin T. Price


Publisher
Pearson Education
Year
2002
Tongue
English
Leaves
694
Edition
1st
Category
Library

⬇  Acquire This Volume

No coin nor oath required. For personal study only.

✦ Synopsis


Four of the authors do a reasonably good job explaining the whole concept of CAS. At times, they seem to be repeating themselves, but the result is that you cannot walk away without understanding what they wanted you to understand because of this repetition.

The downside of this book is the material by Kevin T. Price. They delegated the ASP.NET/Web security to him. Much of his work is a cut and paste of the SDK docs. For his examples, he uses the grid layout of ASP.NET, which makes the declarative code completely unreadable. He leaves in all of the code generated by Visual Studio.NET, despite its irrelevance. He spends a great deal of time discussing IIS configuration, which you might argue is not relevant to the subject matter at hand (this should be a very specialized book, and it is everywhere else). He refers us to a code download on the Sam's website - unfortunately, Sam's is not the publisher of this book. He puts in some sample JSP code for no apparent reason, apparently to teach us about diversity in the web environment. When you buy a book on .NET Framework Security, it is probably because you are interested in .NET, and not because you are interested in the web development ecosystem. Finally, his grand finale chapter is on writing a secure web application. All he manages to achieve here is to create a forms auth login page. Even more troubling is the fact that this sample - in a book on security - has a glaring SQL Injection Vulnerability. The one thing he creates is completely and disturbingly wrong.

Web developers who buy this book to write more secure applications are likely to end up writing even worse applications by implementing his ideas.

Read this book if you want to learn about CAS. Do not stop at this book if you actually need to write secure web applications - in fact, don't even start here. You're better off sticking with the PAG materials.


πŸ“œ SIMILAR VOLUMES


.NET Framework Security
✍ Brian A. LaMacchia, Sebastian Lange, Matthew Lyons, Rudi Martin, Kevin T. Price πŸ“‚ Library πŸ“… 2002 πŸ› Addison-Wesley Professional 🌐 English

.NET Framework Security provides the ultimate high-end comprehensive reference to all of the new security features available in .NET. Through extensive code samples and step-by-step walkthroughs of configuration techniques, the reader is taken deep into the world of secure applications. Demonstratio

.NET Framework Security
✍ Brian A. LaMacchia, Sebastian Lange, Matthew Lyons, Rudi Martin, Kevin T. Price πŸ“‚ Library πŸ“… 2002 πŸ› Pearson Education 🌐 English

In 1997, Microsoft embarked on a "bet the company" strategy that was to reinvent the way the company did business. Even before its release, .NET made major strides in reinventing the way that software developers viewed the software they wrote. Now that it is released, .NET and the .NET Framework wil

Microsoft .NET Framework Security
✍ Roopendra Jeet Sandhu, Surbhi Malhotra πŸ“‚ Library πŸ“… 2002 πŸ› Muska & Lipman/Premier-Trade 🌐 English

Microsoft .NET Framework provides several mechanisms for protecting resources and code from unauthorized code and users. This book walks you through the process of writing .NET code, allowing them to create secure systems and applications using the .NET Framework security cover. It goes over all the

.NET Framework Essentials, 2nd Edition:
✍ Hoang Lam, Thuan L. Thai πŸ“‚ Library πŸ“… 2002 πŸ› O'Reilly Media 🌐 English

.NET Framework Essentials, 2nd Edition is an objective, concise, and technical overview of the new Microsoft .NET Framework for developing web applications and services. Specifically written for intermediate to advanced VB, C/C++, Java, and Delphi developers, .NET Framework Essentials, 2nd Edition

.Net Framework Essentials
✍ Thuan L. Thai, Hoang Lam πŸ“‚ Library πŸ“… 2001 πŸ› O’Reilly 🌐 English

I went to my local bookstore to get a functional understanding of ".NET". My previous readings had been hit and miss and provided little understanding of the new platform. This book provided that understanding. The writeups on the CLR, assemblies, garbage collection, net components, web services, e