Skip to Content
Professional ASP.NET MVC 4
book

Professional ASP.NET MVC 4

by Jon Galloway, Phil Haack, Brad Wilson, K. Scott Allen, Scott Hanselman
October 2012
Intermediate to advanced
504 pages
13h 22m
English
Wrox
Content preview from Professional ASP.NET MVC 4

Security Recap and Helpful Resources

Table 7.1 recaps the threats and solutions to some common web security issues.

Table 7.1 ASP.NET Security

Threat Solutions
Complacency Educate yourself. Assume your applications will be hacked. Remember that it's important to protect user data.
Cross-Site Scripting (XSS) HTML-encode all content. Encode attributes. Remember JavaScript encoding. Use AntiXSS.
Cross-Site Request Forgery (CSRF) Token verification. Idempotent GETs. HttpReferrer validation.
Over-Posting Use the Bind attribute to explicitly whitelist fields. Use blacklists sparingly.

ASP.NET MVC gives you the tools you need to keep your website secure, but it's up to you to apply them wisely. True security is an ongoing effort that requires that you monitor and adapt to an evolving threat. It's your responsibility, but you're not alone. Plenty of great resources are available, both in the Microsoft web development sphere and in the Internet security world at large. Table 7.2 shows a list of resources to get you started.

Table 7.2 Security Resources

Resource URL
Microsoft Security Developer Center http://msdn.microsoft.com/en-us/security/default.aspx
Book: Beginnning ASP.NET Security (Barry Dorrans) http://www.wrox.com/WileyCDA/WroxTitle/Beginning-ASP-NET-Security.productCd-0470743654.html
Free ebook: OWASP Top 10 for .NET developers http://www.troyhunt.com/2010/05/owasp-top-10-for-net-developers-part-1.html
Microsoft Code Analysis Tool .NET (CAT.NET) http://www.microsoft.com/downloads/details ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Professional DevExpress™ ASP.NET Controls

Professional DevExpress™ ASP.NET Controls

Paul Kimmel, Julian Bucknall, Joe Kunk
ASP.NET 4 Unleashed

ASP.NET 4 Unleashed

Stephen Walther, Kevin Hoffman, Nate Dudek
Beginning ASP.NET MVC 4

Beginning ASP.NET MVC 4

José Rolando Guay Paz

Publisher Resources

ISBN: 9781118416754Purchase book