Web Service, restricting access?

Posted on 2008-11-19
Last Modified: 2013-12-17
Using VS2005 Professional Edition I just created a basic Web Service on Windows Server 2003 and added a web method placed it on my LIVE server...

I then created a new website project and added a reference to the Web Service on the LIVE service (

In my website project I can now access the functions in the Web Service and all works great.


But, here is my problem, it was almost too easy, surely anyone could do the same, if they managed to find out the name of the .asmx file on the LIVE server, then they would have access to my web service and all the functions inside. Ultimately I want to fill this service with database functions.

How can I restrict access to this web service or make it so that only my own .NET websites can reference this service?

Question by:blazewada
    1 Comment
    LVL 14

    Accepted Solution

    One way to make it a little more difficult for someone to add a reference is to follow the steps on this site:     IT shows how to modify the web config to not server that data up.   Keep in mind there is a typo in there sample    The paret that says  <removename="..."/>   should be   <remove name="..."/>   it is missing the space.

    For better security, implementing some form of authentication would be a really good idea as well.  If possible, using certificates to prove your application identity that would be probably the best.  Even implementing user name and password is a start.   keep in mind that even if you block access, if you don't use https  it is still unencrypted data across the network that can be sniffed.  You may want to look into ws-security   or some other enchanced security for web services.

    Featured Post

    What Should I Do With This Threat Intelligence?

    Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

    Join & Write a Comment

    This document covers how to connect to SQL Server and browse its contents.  It is meant for those new to Visual Studio and/or working with Microsoft SQL Server.  It is not a guide to building SQL Server database connections in your code.  This is mo…
    Here I am going to explain creating proxies at runtime for WCF Service. So basically we use to generate proxies using Add Service Reference and then giving the Url of the WCF service then generate proxy files at client side. Ok, what if something ge…
    Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…
    Internet Business Fax to Email Made Easy - With eFax Corporate (, you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

    754 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    20 Experts available now in Live!

    Get 1:1 Help Now