|
|
libcats.org
.NET Framework SecurityBrian A. LaMacchia, Sebastian Lange, Matthew Lyons, Rudi Martin, Kevin T. PriceFour of the authors do a reasonably good job explaining the whole concept of CAS. At times, they seem to be repeating themselves, but the result is that you cannot walk away without understanding what they wanted you to understand because of this repetition.
The downside of this book is the material by Kevin T. Price. They delegated the ASP.NET/Web security to him. Much of his work is a cut and paste of the SDK docs. For his examples, he uses the grid layout of ASP.NET, which makes the declarative code completely unreadable. He leaves in all of the code generated by Visual Studio.NET, despite its irrelevance. He spends a great deal of time discussing IIS configuration, which you might argue is not relevant to the subject matter at hand (this should be a very specialized book, and it is everywhere else). He refers us to a code download on the Sam's website - unfortunately, Sam's is not the publisher of this book. He puts in some sample JSP code for no apparent reason, apparently to teach us about diversity in the web environment. When you buy a book on .NET Framework Security, it is probably because you are interested in .NET, and not because you are interested in the web development ecosystem. Finally, his grand finale chapter is on writing a secure web application. All he manages to achieve here is to create a forms auth login page. Even more troubling is the fact that this sample - in a book on *security* - has a glaring SQL Injection Vulnerability. The one thing he creates is completely and disturbingly wrong. Web developers who buy this book to write more secure applications are likely to end up writing even worse applications by implementing his ideas. Read this book if you want to learn about CAS. Do not stop at this book if you actually need to write secure web applications - in fact, don't even start here. You're better off sticking with the PAG materials.
Популярные книги за неделю:
Проектирование и строительство. Дом, квартира, садАвтор: Петер Нойферт, Автор: Людвиг Нефф
Размер книги: 20.83 Mb
Система упражнений по развитию способностей человека (Практическое пособие)Автор: Петров Аркадий НаумовичКатегория: Путь к себе
Размер книги: 818 Kb
Сотворение мира (3-х томник)Автор: Петров Аркадий НаумовичКатегория: Путь к себе
Размер книги: 817 Kb
Радиолюбительские схемы на ИС типа 555Автор: Трейстер Р.Категория: Электротехника и связь
Размер книги: 13.64 Mb
Только что пользователи скачали эти книги:
Квантовая механика - проблемы и парадоксыАвтор: Прохоров Л.В.Категория: Physics, Quantum mechanics
Размер книги: 1.04 Mb
21st Century Robotics (Scientific American Special Online Issue No. 14)Автор: Scientific American
Размер книги: 1.02 Mb
Science and Art (Scientific American Special Online Issue No. 21)Автор: Scientific American
Размер книги: 1.29 Mb
The Search for Alien Life (Scientific American Special Online Issue No. 4)Автор: Scientific American, Автор: inc.
Размер книги: 1.48 Mb
Germ Wars (Scientific American Special Online Issue No. 9)Автор: Scientific American
Размер книги: 2.97 Mb
Tackling Major Killers: Infectious Diseases (Scientific American Special Online Issue No. 22)Автор: Scientific American
Размер книги: 2.33 Mb
Diet and Health (Scientific American Special Online Issue No. 11)Автор: Scientific American
Размер книги: 1.17 Mb
Mysteries of the Milky Way (Scientific American Special Online Issue No. 15)Автор: Scientific American
Размер книги: 1.93 Mb
HIV: 20 Years of Research (Scientific American Special Online Issue No. 7)Автор: Scientific American
Размер книги: 2.80 Mb
|
|
|