您现在的位置: 万盛学电脑网 >> 程序编程 >> 网络编程 >> asp.net编程 >> 正文

如何加强asp.net 1.1 / 2.0 安全性

作者:佚名    责任编辑:admin    更新时间:2022-06-22

 

  ASP.NET 1.1:

打开 C:WINDOWSMicrosoft.NETFrameworkv1.1.4322CONFIGmachine.config

设置:
< location allowOverride="false">

< identity impersonate="true" userName="" password=""/>

ASP.NET 2.0 以上:
C:WINDOWSMicrosoft.NETFrameworkv2.0.50727CONFIGweb.config

设置:
< identity impersonate="true"/>

如果没有此两项,分别进行增加:

< location allowOverride="true">  改为:< location allowOverride="false">
        < system.web>
            < securityPolicy>
                < trustLevel name="Full" policyFile="internal"/>
                < trustLevel name="High" policyFile="web_hightrust.config"/>
                < trustLevel name="Medium" policyFile="web_mediumtrust.config"/>
                < trustLevel name="Low" policyFile="web_lowtrust.config"/>
                < trustLevel name="Minimal" policyFile="web_minimaltrust.config"/>
            < /securityPolicy>
        < trust level="Full" originUrl=""/>
        < identity impersonate="true"/>  < !--  这里增加 -->
        < /system.web>
    < /location>