Home > Microsoft .Net Development Tips > Application Testing and Security > Special Report: Securing applications -- The new frontier in security
Win Development Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

APPLICATION TESTING AND SECURITY

Special Report: Securing applications -- The new frontier in security


Techra LLC
02.03.2006
Rating: --- (out of 5)


Office Development Channel
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Security should not stop at the firewall. Vulnerable applications can lead to the type of data theft, revenue loss and litigation that gives IT professionals nightmares. In "Securing Applications -- The New Frontier in Security," Jim Zimmerman of Techra LLC examines recent analysis of application security, identifies 10 critical vulnerabilities and provides recommendations for addressing each issue.

Tidbits of advice for application developers include the following:

  • When building an app, never allow administrator access in the front door.
  • Make sure your app can handle errors gracefully -- that is, make

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


    RELATED CONTENT
    Application Testing and Security
    Test-driven development in .NET yields complete unit test coverage
    How to write installers in Vista that work correctly under UAC
    How to elevate programs' privileges correctly using Vista's UAC
    Internet Explorer 8 beta's development tools add source visualizations
    Microsoft previews new features in Visual Studio 2010
    Advanced Windows Debugging Book Chapter and Podcast
    Book excerpt: Advanced Windows Debugging
    Book excerpt: Pragmatic unit testing in C# with NUnit
    Security interoperability with .NET/WSE and WebLogic Workshop 8.1
    How to avoid regression bugs while adding new features

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary


    sure it responds with results that are helpful but keep internal details hidden.

  • Use commercial and open-source tools to test your existing environment for vulnerabilities.
  • Set a minimum security baseline configuration standard for development and production. This minimum should address security feature configuration, role permissions and security profiles and an evaluation of what system services are no longer needed.
  • Above all, know what vulnerabilities may exist and figure out how to prevent them before plunging headlong into development.

    [IMAGE] Read more about Zimmerman's report here.

    Rate this Tip
    To rate tips, you must be a member of SearchWinDevelopment.com.
    Register now to start rating these tips. Log in if you are already a member.




    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



  • Database Programming Solutions - .NET XML, Visual Studio LINQ, ORM .NET
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts