Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Web Service, restricting access?

Posted on 2008-11-19
1
Medium Priority
?
273 Views
Last Modified: 2013-12-17
Using VS2005 Professional Edition I just created a basic Web Service on Windows Server 2003 and added a web method placed it on my LIVE server...

I then created a new website project and added a reference to the Web Service on the LIVE service (www.domain.com/servicename.asmx)

In my website project I can now access the functions in the Web Service and all works great.


...

 
But, here is my problem, it was almost too easy, surely anyone could do the same, if they managed to find out the name of the .asmx file on the LIVE server, then they would have access to my web service and all the functions inside. Ultimately I want to fill this service with database functions.

How can I restrict access to this web service or make it so that only my own .NET websites can reference this service?

Thanks!
0
Comment
Question by:blazewada
1 Comment
 
LVL 14

Accepted Solution

by:
jjardine earned 1500 total points
ID: 23001470
One way to make it a little more difficult for someone to add a reference is to follow the steps on this site:  http://www.15seconds.com/issue/040609.htm     IT shows how to modify the web config to not server that data up.   Keep in mind there is a typo in there sample    The paret that says  <removename="..."/>   should be   <remove name="..."/>   it is missing the space.

For better security, implementing some form of authentication would be a really good idea as well.  If possible, using certificates to prove your application identity that would be probably the best.  Even implementing user name and password is a start.   keep in mind that even if you block access, if you don't use https  it is still unencrypted data across the network that can be sniffed.  You may want to look into ws-security   or some other enchanced security for web services.
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Real-time is more about the business, not the technology. In day-to-day life, to make real-time decisions like buying or investing, business needs the latest information(e.g. Gold Rate/Stock Rate). Unlike traditional days, you need not wait for a fe…
This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
Integration Management Part 2
Is your OST file inaccessible, Need to transfer OST file from one computer to another? Want to convert OST file to PST? If the answer to any of the above question is yes, then look no further. With the help of Stellar OST to PST Converter, you can e…
Suggested Courses
Course of the Month10 days, 7 hours left to enroll

569 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question