or
Sign in to turn on 1-Click ordering.
 
 
Express Checkout with PayPhrase
What's this? | Create PayPhrase
Sorry!
More Buying Choices
36 used & new from $0.25

Have one to sell? Sell yours here
 
   
.NET Framework Security
 
See larger image
 
Tell the Publisher!
I’d like to read this book on Kindle

Don’t have a Kindle? Get your Kindle here.
 
  

.NET Framework Security (Paperback)

~ Brian A. LaMacchia (Author), Sebastian Lange (Author), Matthew Lyons (Author), Rudi Martin (Author), Kevin T. Price (Author)
3.8 out of 5 stars  See all reviews (13 customer reviews)

List Price: $57.99
Price: $42.33 & this item ships for FREE with Super Saver Shipping. Details
You Save: $15.66 (27%)
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
Usually ships within 9 to 13 days.
Ships from and sold by Amazon.com. Gift-wrap available.

9 new from $4.90 27 used from $0.25

Frequently Bought Together

.NET Framework Security + .NET Security Programming (Gearhead Press - In the Trenches) + Programming .NET Security
Price For All Three: $108.50

Some of these items ship sooner than the others. Show details

  • This item: .NET Framework Security by Brian A. LaMacchia

    Usually ships within 9 to 13 days.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • .NET Security Programming (Gearhead Press - In the Trenches) by Donis Marshall

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details

  • Programming .NET Security by Adam Freeman

    In Stock.
    Ships from and sold by Amazon.com.
    This item ships for FREE with Super Saver Shipping. Details


Customers Who Bought This Item Also Bought

Applied Microsoft® .NET Framework Programming (Pro-Developer)

Applied Microsoft® .NET Framework Programming (Pro-Developer)

by Jeffrey Richter
4.6 out of 5 stars (88)  $44.99
Programming .NET Security

Programming .NET Security

by Adam Freeman
4.9 out of 5 stars (7)  $29.67
Microsoft® ADO.NET 2.0 Step by Step (Step By Step (Microsoft))

Microsoft® ADO.NET 2.0 Step by Step (Step By Step (Microsoft))

by Rebecca M. Riordan
2.6 out of 5 stars (19)  $39.99
Microsoft® .NET: Architecting Applications for the Enterprise (PRO-Developer)

Microsoft® .NET: Architecting Applications for the Enterprise (PRO-Developer)

by Dino Esposito
4.8 out of 5 stars (20)  $29.69
Developing More-Secure Microsoft® ASP.NET 2.0 Applications (Pro Developer)

Developing More-Secure Microsoft® ASP.NET 2.0 Applications (Pro Developer)

by Dominick Baier
Explore similar items

Editorial Reviews

Product Description

The definite security reference and guide to the new programming platform from Microsoft. Written by people who have designed and implemented the security features and infrastructure in the .NET Framework that ASP.NET, C#, VB or Managed C++ applications run on. Softcover.


From the Back Cover

In 1997, Microsoft embarked on a "bet the company" strategy that was to reinvent the way the company did business. Even before its release, .NET made major strides in reinventing the way that software developers viewed the software they wrote.

Now that it is released, .NET and the .NET Framework will change the software development process for good.

.NET Framework Security provides the ultimate high-end comprehensive reference to all of the new security features available in .NET. Through extensive code samples and step-by-step walkthroughs of configuration techniques, the reader is taken deep into the world of secure applications. Demonstrations of creating custom procedures and a full explanation of each aspect separate this book from many other "lecture books." Many of the concepts expressed in this book are not only viable in .NET, but on the Internet in general. These factors combined make this the one reference that every developer and system administrator should have.

.NET Framework Security provides

  • An extensive introduction to explanation of Code Access Security, the powerful new security system shipping in the .NET Framework
  • Information on how to write and test safe applications using the .NET Framework
  • Extensive coverage on how to effectively administer .NET Framework security
  • In-depth introduction to the cryptography library shipping in the .NET Framework, including an introduction to XML digital signatures
  • An overview of all of the new security features available in .NET
  • Code samples that can be used to implement security on your own Web site or application
  • Step-by-step guidelines for modifying the various configuration files associated with .NET, and an explanation of the elements involved
  • Instructions for all of the aspects of security in the CLR and what it means
  • How to use ASP.NET to create a secure application
  • Explanations for using the CryptoAPI libraries to create your own custom functionality
  • Guidelines on how to create secure network applications as well as applications that exist on the Internet
  • Detailed examples of how to establish security parameters in IIS that relate to ASP.NET
  • Instructions for administering .NET applications hosted in IE



067232184XB04232002

Product Details

  • Paperback: 816 pages
  • Publisher: Pearson Education; 1st edition (April 24, 2002)
  • Language: English
  • ISBN-10: 067232184X
  • ISBN-13: 978-0672321849
  • Product Dimensions: 9.1 x 7.3 x 1.8 inches
  • Shipping Weight: 2.8 pounds (View shipping rates and policies)
  • Average Customer Review: 3.8 out of 5 stars  See all reviews (13 customer reviews)
  • Amazon.com Sales Rank: #1,011,799 in Books (See Bestsellers in Books)

What Do Customers Ultimately Buy After Viewing This Item?

.NET Framework Security
49% buy the item featured on this page:
.NET Framework Security 3.8 out of 5 stars (13)
$42.33
Programming .NET Security
17% buy
Programming .NET Security 4.9 out of 5 stars (7)
$29.67
.NET Security
13% buy
.NET Security 3.8 out of 5 stars (4)
$44.95
.NET Development Security Solutions
11% buy
.NET Development Security Solutions 5.0 out of 5 stars (2)
$44.99

Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
 

Your tags: Add your first tag
 

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

 

Customer Reviews

13 Reviews
5 star:
 (6)
4 star:
 (3)
3 star:    (0)
2 star:
 (3)
1 star:
 (1)
 
 
 
 
 
Average Customer Review
3.8 out of 5 stars (13 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
15 of 16 people found the following review helpful:
4.0 out of 5 stars Best security infrastructure book I've read, February 7, 2003
This is the best book about the security infrastructure of Microsoft .NET Framework that I have ever read. This book has brought me the overall picture of the .NET security system: How does the system work and interact with the existing security system on Win NT platform? In addition, the book is clearly written, well- organized, and full of in-depth information.

Overall, I consider this is an excellent book which could satisfy the security needs for all .NET developers and administrators.

This book is divided into five sections:

1. Introduction to the .NET Developer Platform Security:

This section provides an introduction to the .NET Framework platform and all of the new security features available. Although this section describes only brief information, I still recommend that every one should read it first before jumping to the others. The first section "provides common background material for the topic-specific discussions in the remainder of the book."

2. Code Access Security Fundamentals:


This section provides an extensive introduction to Code Access Security, a powerful and surprising code-based security feature shipping in .NET Framework. Many new terminologies are explained: Evidence, Permissions, Stack Walk, Code Groups, Policy Levels, etc.

This section is really difficult. I felt overwhelmed with too many new concepts and skipped it. However, after reading some chapters of the next section, I realized that the code-based security concept is the keystone for the entire security system. I had to come back to section two and read it carefully. Learn from my lesson, you should try to understand it at the first time you read it.

3. ASP.NET and Web Services Security Fundamentals:

This section provides brief information about server-side security features of ASP.NET and Web Services.

4. .NET Framework Security Administration:

This section provides a comprehensive guide to administer .NET Framework security. It shows you when and how to make modifications. Some topics are presented as tutorials. It is very to easy to capture and follow the steps.

5. .NET Framework Security for Developers

The final section is devoted to developers. It provides all needed information to build secure assemblies, web sites, applications, and web services. It also provides an in-depth introduction to the cryptography library shipping in the .NET Framework and to XML digital signatures. For developers who don't have enough time to read the whole book, this is the section that you should spend your time on. -- Review by Trung N.

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
13 of 14 people found the following review helpful:
2.0 out of 5 stars Good material on CAS, TERRIBLE material on ASP.NET Security, April 29, 2004
By C. Jackson (New York, NY United States) - See all my reviews
(REAL NAME)   
Four of the authors do a reasonably good job explaining the whole concept of CAS. At times, they seem to be repeating themselves, but the result is that you cannot walk away without understanding what they wanted you to understand because of this repetition.

The downside of this book is the material by Kevin T. Price. They delegated the ASP.NET/Web security to him. Much of his work is a cut and paste of the SDK docs. For his examples, he uses the grid layout of ASP.NET, which makes the declarative code completely unreadable. He leaves in all of the code generated by Visual Studio.NET, despite its irrelevance. He spends a great deal of time discussing IIS configuration, which you might argue is not relevant to the subject matter at hand (this should be a very specialized book, and it is everywhere else). He refers us to a code download on the Sam's website - unfortunately, Sam's is not the publisher of this book. He puts in some sample JSP code for no apparent reason, apparently to teach us about diversity in the web environment. When you buy a book on .NET Framework Security, it is probably because you are interested in .NET, and not because you are interested in the web development ecosystem. Finally, his grand finale chapter is on writing a secure web application. All he manages to achieve here is to create a forms auth login page. Even more troubling is the fact that this sample - in a book on *security* - has a glaring SQL Injection Vulnerability. The one thing he creates is completely and disturbingly wrong.

Web developers who buy this book to write more secure applications are likely to end up writing even worse applications by implementing his ideas.

Read this book if you want to learn about CAS. Do not stop at this book if you actually need to write secure web applications - in fact, don't even start here. You're better off sticking with the PAG materials.

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
9 of 9 people found the following review helpful:
5.0 out of 5 stars The definite security reference for .NET applications, May 1, 2002
By A Customer
Make no mistake,as you will get your hands wet programming Micrsosoft's "managed code" (C#, VB or ASP.NET apps), you will eventually encounter the all pervasive and extensive security system that is integrated in .Net.
This book is the definite security reference and guide to the new programming platform that Micrsosoft has shipped - and the only book of its kind on the market as far as I can see. It has been written by the people who have designed and implemented the security features and infrastructure in the .NET Framework that ASP.NET, C#, VB or Managed C++ applications run on.
Its stuffed with sample code and hands-on tips, and comes with extensive sections geared specifically towards developers and admins. Chapters are well contained and you get the kind of insider information only the people who have actually build and designed the system would be able to give you.
800 plus pages of security information for the Amazon price is quite a good bang for the buck,so I highly recommend this book as I think it will be a good learning aid in trying to understand .NEt security and remain valuable as a reference work afterwards.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

4.0 out of 5 stars A great starting point
This book is an excellent starting point for understanding the .NET framework security mechanisms. Especially code access security. Read more
Published on April 17, 2003 by Mark Levison

4.0 out of 5 stars Good Information
When I was assigned the task of finding out what .NET security was all about in the web environment, I didn't know what I was getting into. The whole . Read more
Published on April 12, 2003 by O. Durojaiye

1.0 out of 5 stars A dictionary of .Net security terms
The book is organized like a dictionary of .Net security terms. It failed to convey the cohesiveness of the security modules. Read more
Published on December 17, 2002

5.0 out of 5 stars Great book - in depth
This book was great. It did not just scratch the surface like most books, but it went into depth where it was needed. This is the book to have for .NET Security.
Published on August 22, 2002 by Matt Garing

5.0 out of 5 stars In depth
Excellent and indepth... although it starts out slow.

If you really want to know all there is to know about code access security, this is the book for you. Read more

Published on July 5, 2002 by Robert M. Downey

2.0 out of 5 stars Very poor on some topics
This book covers some topics such as code access security really well but others like ASP.NET security really badly.

The ASP. Read more

Published on July 3, 2002

5.0 out of 5 stars Very in-depth, excellent
This was awesome. The authors picked apart each new piece of the security model and explained it most clearly. Read more
Published on May 19, 2002

2.0 out of 5 stars good
A good book, but too long for the subject; more of a reference for those who know the subject, rather than a learning tool for those just learning the subject.
Published on May 6, 2002

5.0 out of 5 stars This is the book you're looking for.
It's probably not going to make your in-laws love you, but it is the right book for .Net. Like all things digital, . Read more
Published on May 1, 2002 by Erik W. Davis

5.0 out of 5 stars This is the book you're looking for.
It's probably not going to make your in-laws love you, but it is the right book for .Net. Like all things digital, . Read more
Published on May 1, 2002 by Erik W. Davis

Only search this product's reviews



Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Discussion Replies Latest Post
Textbooks for Kindle DX? 61 4 days ago
textbook scam 66 9 days ago
Search Customer Discussions
Search all Amazon discussions
   




Product Information from the Amapedia Community

Beta (What's this?)


Look for Similar Items by Category


Look for Similar Items by Subject

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Your Recent History

 (What's this?)

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.