Click here to Skip to main content
15,916,683 members
Home / Discussions / ASP.NET
   

ASP.NET

 
AnswerRe: Clear a Page that is being loaded by using .load jQuery Pin
dan!sh 20-Aug-18 20:46
professional dan!sh 20-Aug-18 20:46 
GeneralRe: Clear a Page that is being loaded by using .load jQuery Pin
indian14322-Aug-18 6:15
indian14322-Aug-18 6:15 
QuestionHash/Salt question Pin
Member 1395350318-Aug-18 4:14
Member 1395350318-Aug-18 4:14 
AnswerRe: Hash/Salt question Pin
jkirkerx18-Aug-18 8:23
professionaljkirkerx18-Aug-18 8:23 
GeneralRe: Hash/Salt question Pin
Member 1395350318-Aug-18 11:05
Member 1395350318-Aug-18 11:05 
GeneralRe: Hash/Salt question Pin
jkirkerx18-Aug-18 12:59
professionaljkirkerx18-Aug-18 12:59 
GeneralRe: Hash/Salt question Pin
Member 1395350318-Aug-18 17:56
Member 1395350318-Aug-18 17:56 
AnswerRe: Hash/Salt question Pin
Vincent Maverick Durano21-Aug-18 10:13
professionalVincent Maverick Durano21-Aug-18 10:13 
GeneralRe: Hash/Salt question Pin
Member 1395350321-Aug-18 10:50
Member 1395350321-Aug-18 10:50 
GeneralRe: Hash/Salt question Pin
Vincent Maverick Durano21-Aug-18 11:05
professionalVincent Maverick Durano21-Aug-18 11:05 
GeneralRe: Hash/Salt question Pin
Member 1395350321-Aug-18 22:07
Member 1395350321-Aug-18 22:07 
GeneralRe: Hash/Salt question Pin
Richard Deeming22-Aug-18 3:03
mveRichard Deeming22-Aug-18 3:03 
GeneralRe: Hash/Salt question Pin
Vincent Maverick Durano22-Aug-18 3:12
professionalVincent Maverick Durano22-Aug-18 3:12 
Questionhow to hold browsing path in fileupload control(i want to choose my choice folder) & How to get uploaded file path ,while click on show in folder(Show in Folder)? Pin
BNB-GOWD16-Aug-18 7:58
BNB-GOWD16-Aug-18 7:58 
AnswerRe: how to hold browsing path in fileupload control(i want to choose my choice folder) & How to get uploaded file path ,while click on show in folder(Show in Folder)? Pin
F-ES Sitecore16-Aug-18 22:17
professionalF-ES Sitecore16-Aug-18 22:17 
Question.Net Core Dependency Injection, How to architect it, do I need it? Email Queues. Pin
jkirkerx15-Aug-18 8:11
professionaljkirkerx15-Aug-18 8:11 
AnswerRe: .Net Core Dependency Injection, How to architect it, do I need it? Email Queues. Pin
F Margueirat23-Aug-18 8:18
F Margueirat23-Aug-18 8:18 
QuestionHow to manage a combined role + organization security in MVC? Pin
F Margueirat15-Aug-18 4:34
F Margueirat15-Aug-18 4:34 
AnswerRe: How to manage a combined role + organization security in MVC? Pin
jkirkerx15-Aug-18 8:35
professionaljkirkerx15-Aug-18 8:35 
GeneralRe: How to manage a combined role + organization security in MVC? Pin
F Margueirat20-Aug-18 7:00
F Margueirat20-Aug-18 7:00 
GeneralRe: How to manage a combined role + organization security in MVC? Pin
jkirkerx20-Aug-18 7:23
professionaljkirkerx20-Aug-18 7:23 
QuestionBrowser Security Pin
saurabh.15in14-Aug-18 3:39
saurabh.15in14-Aug-18 3:39 
AnswerRe: Browser Security Pin
Richard Deeming14-Aug-18 4:15
mveRichard Deeming14-Aug-18 4:15 
If your site is always running over HTTPS, then requests and responses cannot be read or modified by a MitM. The only exceptions would be:
  1. The attacker has convinced a rogue CA to issue an invalid cert for your site.
    This would likely be detected pretty quickly, and would result in browsers dropping that CA from their "trusted CAs" list.
    HPKP[^] can help to prevent this; but if the user's first access to your site is via a compromised network, the HPKP information could also be removed or compromised.
     
  2. The attacker has compromised the user's computer, and installed their own root cert in the trusted store, allowing them to issue invalid certs for any site.
    HPKP might help in this case; but if the user's computer has been compromised, the cached pins could also have been deleted or modified.
     
  3. The attacker has compromised the user's computer, and installed malware to modify pages after the browser has downloaded them.
    As a site owner, there is nothing you can do to prevent this sort of attack. Even if you add CSP[^] to control which scripts can run, the malware can just remove that header.

A more likely scenario is if your site is initially served over HTTP, in which case, a MitM attacker can prevent the redirection to HTTPS, and is free to do whatever they want with your site's content.

HSTS[^] can help to prevent this, but your user would need to access your site via a clean network first.

You can request to have your site included on the "preload" list[^], which would ensure it's only ever accessed over HTTPS, even for new users. But if you ever wanted to switch back, it could take many months for your site to be removed.



"These people looked deep within my soul and assigned me a number based on the order in which I joined."
- Homer

GeneralRe: Browser Security Pin
saurabh.15in15-Aug-18 21:28
saurabh.15in15-Aug-18 21:28 
QuestionI am getting the following error in my Production Server: Error Message: The communication object, System.ServiceModel.Channels.ServiceChannel, cannot be used for communication because it is in the Faulted state. Pin
indian14313-Aug-18 7:59
indian14313-Aug-18 7:59 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.