Security :: Restrict Access To Site From Outside Office?
		
			Nov 9, 2010
				I am faced with a rather tricky issue. I am developing a web application that resides beneath a web site. The web application is actually meant for the employees of the company owning the web site. The employees can access the web app from the login facility on the site.
The situation demands that an employee must be able to login to the app only from the office machines and not from anywhere outside. I thought of a logic where in the IP address of the machine in which the employee sits will be stored against the employee profile and when he logs in, the authentication will check for user credentials as well as whether he is logging from the designated IP. If not he is not allowed access to the app even if the login credentials where correct.
I am not sure if this is a good way, because I feel tricky persons can give the same IP of the office machine in another machine, say at home and the logic is broken. Can somebody provide me a better way of solving the issue. I am using ASP.Net login control for user login.
	
	View 3 Replies
  
    
	Similar Messages:
	
    	
    	
        Feb 22, 2010
        We have a scenario whereby we are hosting an ASP.NET MVC web site on behalf of someone else.The customer in this case wants us to restrict access to the web site, to those users who have logged in to their main portal. They should then only be able to get to our web site via a link from that portal.At this point I'm not yet sure what technology or authentication mechanism the 3rd party are using but just wanted to clarify what the possible options might be.If we call our hosted site B, and their portal web site A,as I see it we could:Check the referrer for all requests to B, unless they've come from A they can't get inCheck for a specific cookie (assuming A uses cookies)
	View 2 Replies
   
  
    
	
    	
    	
        Aug 18, 2010
        I'm writing a simple Intranet application using windows authentication. I want to restrict access to Safe/UCantSeeMe.aspx. I am aware of the AuthorizeAttribute, but this only works on methods.  I also found a good post on doing this with the MVC pattern, but I'm not using MVC. This can be done with roles in forms based security. I read on MSDN that using windows based security means roles are based on groups, but it doesn't go into any detail. how can I restrict access to Safe/UCantSeeMe.aspx?
	View 1 Replies
   
  
    
	
    	
    	
        Jan 23, 2010
        [Code]....
Trying to restrict access to folder but can't?
	View 6 Replies
   
  
    
	
    	
    	
        Oct 13, 2010
        I want to secure a particular set of files in a folder by role type.  I have the following entry (See below)...I notice this doesn't work (I.e., it doesn't secure the file by Role Type.. anyone can access the file).  I've read that I need to map the .WMV extension to the ASp.Net DLL.  
[Code]....
	View 10 Replies
   
  
    
	
    	
    	
        May 12, 2010
        I have just started to use asp.net mvc.
I have read this article about using ntlm authentication
[Code]....
it provides access to specific domain users
[Code]....
I want to restrict access to all my domain users only lets say
[Authorize(Domain="redmond")]
or do I do it via web.config
	View 2 Replies
   
  
    
	
    	
    	
        Mar 17, 2010
        I have a security issue in my web application where user can enter malicious data/can change the page path directory. To avoid these i want to restrict the user by accessing/typing in the URL. 
	View 5 Replies
   
  
    
	
    	
    	
        Jun 10, 2010
        I am deploying a public ASP.NET website on an IIS7 web farm.
The application runs on 3 web servers and is behind a firewall.
We want to create a single page on the website that is accessible only to internal users. It is primarily used for diagnostics, trigger cache expiry, etc.
/admin/somepage.aspx
What is the best way to control access to this page? We need to:
Prevent all external (public) users from accessing the URL. Permit specific internal users to access the page, only from certain IPs or networks.
Should this access control be done at the (a) network level, (b) application level, etc.?
	View 3 Replies
   
  
    
	
    	
    	
        Nov 1, 2010
        I need to restrict access to my website by physical PC. When a user signs up I want to be able to restrict access to one machine for that account so it cannot be shared round, if, for example, somebody else in the same office wanted to access the system on their PC they would need a seperate sign in.
I have done some investigation and I "think" the only way is installing an ActiveX component (which isn't an issue that is restricts to IE only) and then read the users MAC address.  Am I trying to over complicate things or is that the only way?  I realise that MACS can be spoofed but this is not much of an issue.
	View 4 Replies
   
  
    
	
    	
    	
        Jun 29, 2010
        Currently in my application using LDAP to authenticate user to a specific domain & then i check if the user exist in my site database.
Now i need to also allow users who do not belong to this specific LDAP domain to access my site ..How can i make it possible withoput affecting the exisiting users?
	View 1 Replies
   
  
    
	
    	
    	
        Oct 31, 2010
        i want to know the number of users wich access to my site and show it
	View 4 Replies
   
  
    
	
    	
    	
        Mar 25, 2010
        I am trying to find a good pattern to use for user access validation.
Basically on a webforms application I had a framework which used user roles to define access, ie, users were assigned into roles, and "pages" were granted access to a page.  I had a table in the database with all the pages listed in it.  Pages could have child pages that got their access inherited from the parent.
When defining access, I assigned the roles access to the pages.  Users in  the role then had access to the pages.  It is fairly simple to manage as well.  The way I implemented this was on a base class that every page inherited.  On pageload/init I would check the page url and validate access and act appropriately.
However I am now working on a MVC application and need to implement something similar, however I can't find a good way to make my previous solution work. Purely because I don't have static pages as url paths.  Also I am not sure how best to approach this as I now have controllers rather then aspx pages.
I have looked at the MVCSitemapprovider, but that does not work off a database, it needs a sitemap file.  I need control of changing user persmissions on the fly.
	View 2 Replies
   
  
    
	
    	
    	
        Oct 21, 2010
        I have an ASP.net 2.0 website that sits on a Windows XP SP3 box on IIS 5.1.  The website needs to go across a UNC path to another server to grab an image file.  Both boxes are in the same workgroup but no domain is setup.  I have created the same user on both boxes with the same password and the website is using anonymous access using that account.  The account is an admin on both boxes(i know security risk but this is for testing).  File.Exists() just keeps returning false but the file is there.  I suspect it has something to do with the ASPNET account but i'm at a loss.  I've tried aspnet impersonation using that account as well with no luck.
	View 4 Replies
   
  
    
	
    	
    	
        Dec 8, 2010
        I have an internal corporate ASP.NET MVC website. 
Requirement(1): When any person is on the network, they can access this site EXCEPT one AD Group (Example: AD_Sales group).
Requirement(2): Also like for example if a person that has the access passes a url (Ex: http://mysite/Home/Index/Product/Letter) to a sales group person, he still should NOT access and need to display a custom message saying "You are not authorised to view this page".
If the scenario is like to issue the access to one AD Group and deny access for all others, it is fairly is. It can done from IIS. I am Wondering how to do this. 
	View 2 Replies
   
  
    
	
    	
    	
        Apr 18, 2010
        i am building a member management site for a sports club, i have all the usual feilds
lastName, firstName, address1, address2, address3 ....
but they also want a photo
when i first made the DB i used access 2010 which uses the 2007 file type which supports attachments, however asp.net doesnt support the 2007 format. and the 2003 file type doesnt support attachments, i assume i use the OLE object data type but i have no idea how i get my aspx page "new.aspx" to upload an attachment. plus i want to restrict the file type to *.jpg
	View 1 Replies
   
  
    
	
    	
    	
        Oct 15, 2010
        I have an intranet site that i set up to windows authentication. It works fine most of the time but some departments wont be able to access the site and will be asked to enter user name and password.I checked their Active Directory account and the only difference i could see was that the  organizational unit parameter was different than the rest of the users.
	View 5 Replies
   
  
    
	
    	
    	
        Aug 18, 2010
        Why can I still access files inside a forms authenticated part of my site? Any webpages say that you need to login to view them, but people can still access images by typing in the address bar. I am using forms authentication with my own database, so none of the aspnetdb services like membership roles etc. Is this a bad way to do things because I'm pretty deep into it now and it would be very difficult to change.
	View 16 Replies
   
  
    
	
    	
    	
        Feb 15, 2011
        How can I Restrict Access to an specific folder, for example I have a folder that Authenticated users upload different files in it. the problem is that every user can access the files via URL in the browser.I don't use asp.net login controls for authenticating and role memberships, I have written login page and roles my self via code behind.
	View 1 Replies
   
  
    
	
    	
    	
        Aug 24, 2010
        I want to be able to restrict page access in a web application deployed in IIS 6.0. Say my web applications has these pages:
a.aspx
b.aspx
c.aspx
d.aspx
The proper way to access is [URL]" From a.aspx the other aspx pages could be loaded. What I want to be prevent is someone typing in: [URL] 
	View 2 Replies
   
  
    
	
    	
    	
        Jan 17, 2010
        How can i prevent users from getting the list of files that exist in my website?
For example when users type on the address bar the WebsiteAddress+/DirectoryToSearch/ they get the list of files in that directory, without getting any permission denied error
Is there any setting in asp.net that am i missing?
	View 1 Replies
   
  
    
	
    	
    	
        Mar 29, 2011
        I need a reliable method to switch off users' access to SSRS dynamically. If you care about the reason, users are not allowed to access SSRS from home, but they are allowed access from within the factory walls.
I can generate a token or event when they arrive at work or leave, no problem, such is the sophistication of our security system.
So I can create a little .net app that pokes SSRS in some way and tells SSRS to allow that username to access reports. When the users leaves the premises, the .net app will prod SSRS to deny that username access.
I considered dynamically adding and removing usernames from the authentication section of web.config in the SSRS root dir, as in <deny=usernamelist />. But given the frequency of changes (dozens per hour at peak times), that seems too intrusive, as it probably causes the restart of the app.
I tried adding usernames to the ACL on the SSRS physical directory (Microsoft SQL ServerMSSQL.2Reporting ServicesReportServer) as deny reader, and for a few brief minutes I thought I had arrived at a solution, but for some reason SSRS decided to serve pages to denied users seemingly at random. Must be cached somewhere, although I can't for the life of me figure out why that would be happening seemingly at random.
I rather like the ACL idea from the perspective of ease of control, and if there's a simple thing i have overlooked in the way SSRS interacts with IIS and NTFS permissions, I hope someone can point it out so I can understand why the ACL seems to be mostly ignored.
	View 1 Replies
   
  
    
	
    	
    	
        Sep 23, 2010
        How to restrict folder access in asp.net like i dun want any other to see my Uploads folder in browser by link http://www.myweb.com/Uploads
	View 3 Replies
   
  
    
	
    	
    	
        Dec 9, 2010
        My server administrator does not allow me to install Microsoft Office in the server.
I have developed a website which converts XML files to Excel and it is using Microsoft.Office.Interop.Excel.
Is there any way I can run this application without installing Microsoft Office in the server?
	View 7 Replies
   
  
    
	
    	
    	
        Jan 14, 2010
        when i would like to restrict files to access only on my Test page , here  i am retriving my files in iframe in Test page, problem occurs when a user authenticated themselves then they will be redirected on welcome page and he can access my files through welcome page on Browser by knowing my Folder Name. but i do'nt want to give permissions to access on welcome page using IBrowser i only want to give my files(.mht files) that should be accessed on iframe. 
this code as shown below doing pretty well in Visual studio "Debug mode but when i deploy this on iis 7.0 then it is not restricting my .mht files so please help , if you have any othe idea to protect then please give me .
[code]....
	View 7 Replies
   
  
    
	
    	
    	
        Jun 14, 2010
        I need to restric access to my admin folder to certain people. Those with no authentication ticket should be redirectered to a "not allowed page". How do I identify all pages in my admin folder. I have so far but is it OK?
If url.Contains("/admin") Then
'If authentication ticket incorrect then
`Response.Redirect("~/notallowed_admin.aspx")`
End If
And not, I cannot use my web.config for this particular issue.
	View 2 Replies