Solved

Securing ASMX pages

Posted on 2004-10-14
4
867 Views
Last Modified: 2008-03-04
I have a ASMX web service page which has several functions. There is a Win app which calls functions from this web service page. This all works fine, except that the ASMX page can be accessed by anybody from the browser. With some of the functions, the user can even enter data into the fields (for functions that require parameters) and click a button to get the result.

How do I prevent users from accessing the ASMX page from the browser (or at least prevent them from using the functions) without affecting how the Win app is used? Thanks.
0
Comment
Question by:hobster
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 3

Accepted Solution

by:
Realmrat earned 25 total points
ID: 12317082
Buy "Building Secure Microsoft ASP.NET Applications" and read the 30 page Chapter 10: Web Services Security.  =]

This really is a big subject.

 - Joe
0
 
LVL 3

Assisted Solution

by:eekj
eekj earned 25 total points
ID: 12326103
Add a function that takes the an encrypted username and password then have your web service check these in a database. If the credentials are correct store the session id for that client in another database table. Each time one of the web service functions is called first check the sessionid from that client to see if they have been validated and only then allow them to execute the main part of the code for that function.
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
VB.NET 2008 - SQL Timeout 9 51
Unable to connect C# program to an SQL database - Exception occurs. 4 61
Problem to Office 1 45
Selenium and Xpath 4 35
Extention Methods in C# 3.0 by Ivo Stoykov C# 3.0 offers extension methods. They allow extending existing classes without changing the class's source code or relying on inheritance. These are static methods invoked as instance method. This…
In order to hide the "ugly" records selectors (triangles) in the rowheaders, here are some suggestions. Microsoft doesn't have a direct method/property to do it. You can only hide the rowheader column. First solution, the easy way The first sol…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
I've attached the XLSM Excel spreadsheet I used in the video and also text files containing the macros used below. https://filedb.experts-exchange.com/incoming/2017/03_w12/1151775/Permutations.txt https://filedb.experts-exchange.com/incoming/201…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question