Input Validation


Check

Description

MarshalByRefObj objects from clients are not accepted without validating the source of the object.

The risk of serialization attacks are mitigated by setting the typeFilterLevel attribute programmatically or in the application's Web.config file.

All field items that are retrieved from serialized data streams are validated as they are created on the server side.




Improving Web Application Security. Threats and Countermeasures
Improving Web Application Security: Threats and Countermeasures
ISBN: 0735618429
EAN: 2147483647
Year: 2003
Pages: 613

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net