
Secure ASP.NET AJAX Development (Digital Short Cut)
Description
Alles über E-Books | Antworten auf Fragen rund um E-Books, Kopierschutz und Dateiformate finden Sie in unserem Info- & Hilfebereich.
Many organizations are diving headfirst into AJAX technologies to make their Web applications richer and more user friendly, but they often do not realize the security implications of the AJAX approach. Microsoft's ASP.NET AJAX technologies, commonly known by the codename "Atlas," and other AJAX frameworks are changing the way Web applications look and are developed, but Web developers are often unaware of the security risks they are introducing into their applications with these emerging technologies.
AJAX fundamentally changes the user experience and server interaction in Web applications, so developers may be taking otherwise secure applications and opening up new angles of attack for hackers. This short cut outlines the increased security risk inherent with AJAX technologies and addresses how developers can use Microsoft's ASP.NET AJAX to implement secure AJAX applications. After discussing Web application security pitfalls that are common in AJAX development, given its focus on increased client processing and more frequent access to Web services and databases, the author focuses on a few key security principles for AJAX developers--demystifying AJAX security and teaching how to develop secure AJAX applications using ASP.NET AJAX Extensions. The short cut concludes with a walkthrough of security testing best practices that will help effectively uncover security problems in AJAX applications during development and testing.
What This Short Cut Covers 3
Section 1: AJAX, ASPNET, and Atlas 4
Section 2: AJAX Security Pitfalls 19
Section 3: Securing ASPNET AJAX 44
Section 4: ASPNET AJAX Security Testing 81
About the Author 92
More details
Person
Jason Schmitt is group product manager for SPI Dynamics, the expert in Web application security assessment and testing. He is responsible for overseeing product strategy and direction for the company's developer and quality-assurance products, which are aimed at helping developers code more secure Web applications. Jason has a long history of work expertise in product management, product development, and technical consulting. Prior to joining SPI Dynamics, Jason held positions at EzGov, where he was a senior manager of product engineering, managing the product development team in the design, implementation, and delivery of Web application framework and development products for e-government. In addition, Jason was consulting manager for EzGov, managing Web application projects and programs for federal, state, and international governments. Prior to EzGov, Jason was a technical consultant for e-commerce provider, Ariba, and a consultant for telecom companies for Andersen Consulting (Accenture). Jason is a frequent speaker and expert resource for the press, and he writes for industry publications on secure software development. He has an MBA from Georgia State University and a BS in mechanical engineering from the Georgia Institute of Technology.
Content
What This Short Cut Covers 3
Section 1: AJAX, ASPNET, and Atlas 4
Section 2: AJAX Security Pitfalls 19
Section 3: Securing ASPNET AJAX 44
Section 4: ASPNET AJAX Security Testing 81
About the Author 92
System requirements
File format: PDF
Copy protection: Watermark-DRM (Digital Rights Management)
System requirements:
- Computer (Windows; MacOS X; Linux): Use the free software Adobe Reader, Adobe Digital Editions, or any other PDF viewer of your choice (see eBook Help).
- Tablet/Smartphone (Android; iOS): Install the free app Adobe Digital Editions or another reading app for eBooks, e.g., PocketBook (see eBook Help).
- E-reader: Bookeen, Kobo, Pocketbook, Sony, Tolino and many more (only limited: Kindle).
The file format PDF always displays a book page identically on any hardware. This makes PDF suitable for complex layouts such as those used in textbooks and reference books (images, tables, columns, footnotes). Unfortunately, on the small screens of e-readers or smartphones, PDFs are rather annoying, requiring too much scrolling.
This eBook uses Watermark-DRM, a „soft” copy protection. This means that there are no technical restrictions to prevent illegal distribution. However, there is a personalised watermark embedded in the eBook that can be used to identify the purchaser of the eBook in the event of misuse and to provide evidence for legal purposes.
For more information, see our eBook Help page.