Wednesday, February 28, 2007
 Friday, February 23, 2007
 Tuesday, February 20, 2007

Another interesting article:

http://www.joelonsoftware.com/articles/customerservice.html

 

Barry

2/20/2007 1:51:00 PM (GMT Standard Time, UTC+00:00)  #    Disclaimer  |  Comments [0]  |  Trackback
 Thursday, February 15, 2007

One of the issues raised by Gleneagles during a penetration test was that the Cookies (session and authentication) did not have the SSL bit set.  This ensures that the cookie information cannot be transmitted through http://

To ensure this in the System.Web configuration section of the sites Web.Config:

1. Add <httpCookies requiresSSL="true" />

2. add the requiresSSL="true" attribute to the forms authentication configuration.

 

Cheers

2/15/2007 3:25:53 PM (GMT Standard Time, UTC+00:00)  #    Disclaimer  |  Comments [0]  |  Trackback
 Monday, February 12, 2007
2/12/2007 6:40:15 PM (GMT Standard Time, UTC+00:00)  #    Disclaimer  |  Comments [0]  |  Trackback
 Thursday, February 01, 2007
2/1/2007 1:03:56 PM (GMT Standard Time, UTC+00:00)  #    Disclaimer  |  Comments [0]  |  Trackback