Global Security Watch > Security Tip: Blocking Access to ASP.NET MVC Views Using ...

you've been HAACKEDhttp://haacked.com/archive/2008/06/25/aspnetmvc-block-view-access.aspx [you've been HAACKED] When you create a new ASP.NET MVC project using our default templates, one of the things you might notice is that there is a web.config file within the Views directory. This file is there specifically to block direct access to a view.

Some related posts from Technorati and Google.

Alvin Ashcraft's Morning Dew[Alvin Ashcraft's Morning Dew] Dew Drop - June 26, 2008: Web Development. How to Build a Task Scheduler System for the ASP.NET - Part 2 (Keyvan Nayyeri); ASP.NET MVC: List Helper Extension Method (Rob Conery); Security Tip: Blocking Access to ASP.NET MVC Views Using Alternative View Engines ...

Jason Haley[Jason Haley] Interesting Finds: June 25, 2008: Web stuff Dion Almaer - Badging Flickr with Dojo Alex_1 - FTP Client and HttpFileDownloader Components(Controls) IE Blog - IE8 and Trustworthy Browsing Stephen Walther - ASP.NET MVC Tip #8 - Create an ASP.NET MVC GridView Helper Method .

Stop Making Sensehttp://gregorybeamer.spaces.live.com/blog/cns!B036196EAF9B34A8!637.entry [Stop Making Sense] Setting up the ASP.NET MVC Membership Starter Kit with SQL Server: I have also included a script for you to run, if you are not big on using the web configuration tool. If you use the script, you will have to set up the following machineKey section in your web.config, as the passwords are encrypted using these settings (NOTE the validation key is on two lines as spaces truncates things -- you must fix that in your web.config when you copy and paste this):

Los Techieshttp://www.lostechies.com/blogs/sean_chambers/archive/2008/06/24/designing-controllers.aspx [Los Techies] Designing Controllers: DynamicActions are a way to create an action in it's own class and then by using attributes, you can hook up the disconnected action to whichever Controllers you wish, passing in parameters that deal with the specific context the DynamicAction is being used in. This works extremely well if the code that needs to be reused is exactly the same except for the objects that it is working with.

ajaxline[ajaxline] Weekly 16.06-23.06: Using a custom VirtualPathProvider can cause OutOfMemoryExceptions. How To Upload Files With ASP.NET Part 2 (screencast).

Windows Live spacehttp://dotnetmagic.spaces.live.com/blog/cns!709F68A62F06375F!166.entry [Windows Live space] ASP.NET MVC: To help make your development experience more comortable the following is a list of 47 of the most interesting and helpful ASP.NET MVC resources available to-date. Now while we can all agree that this post becomes a legacy artifact as soon as I press the "Publish"

Tad Wang's Webloghttp://tadwang.wordpress.com/2008/06/07/links/ [Tad Wang's Weblog] Recent Links: ASP.NET, ASP.NET AJAX, ASP.NET MVC, Silverlight: NET MVC uses, as well as better confirmation, foreign-key, and template support. ASP.NET Testing with Ivonna: Travis Illig blogs about a new testing framework named Ivonna that enables unit testing of ASP.NET web forms.

Jason Haley[Jason Haley] Interesting Finds: June 22, 2008: Web stuff Dan Hounshell - Upgrading Kigg Unit Tests to MVC ASP.NET Preview 3 Mike Ormond - ASP.NET Routing and Authorization. Agile stuff Greg Duncan - Are you “really” using Scrum?

Christopher Steen[Christopher Steen] Link Listing - June 25, 2008: Hosting an entire ASP.NET MVC request for testing purposes ; Security Tip: Blocking Access to ASP.NET MVC Views Using Alternative View Engines

Jason Haley[Jason Haley] Interesting Finds: June 24, 2008: Web stuff Stephen Walther - ASP.NET MVC Tip #7 - Prevent JavaScript Injection Attacks with Html.Encode Samuel Dean - Two Alternative Solutions for Site Analytics IE Programming Team - Securing Cross Site XMLHttpRequest Tom - ASP.

Reflected tags on Technorati: Blog, , , , , ,