Plateforme Level Extreme
Abonnement
Profil corporatif
Produits & Services
Support
Légal
English
Business Objects separate from UI Question - hackers??
Message
Information générale
Forum:
ASP.NET
Catégorie:
The Mere Mortals .NET Framework
Divers
Thread ID:
00937993
Message ID:
00938050
Vues:
13
How do you prevent a user(hacker) from utilizing the businessobject.dll to get access to the database?

In the MM items, it has a getdatset method, by passing all the right keys, the user can get access to the database, and the data.
Worst yet they can reference my dll and then use my own code against me in there app.(insert,deletes,updates)

is mmApp available as a in the webframework as it is in the winforms framework?

If so what i think i might do is in the business object is check to see if the user is logged in, if not then kick out of the business object.


Are you using SQL Server? If so, you can have the application use a specific user name and password instead of using a trusted connection. Just another option...
Précédent
Répondre
Fil
Voir

Click here to load this message in the networking platform