Blue Theme Orange Theme Green Theme Red Theme
 
Home | Forums | ASP.NET 2.0 Tutorials | Web Services | How Do I...? | Class Browser | WPF Quick Starts | Advertise with Us
 | Consulting  
Submit an Article Submit a Blog 
 Jump to
Skip Navigation Links
TechnologyExpand Technology
WebsiteExpand Website
6 Months Free & No Setup Fees ASP.NET Hosting!
Search :       Advanced Search »
Home » Visual Web Developer 2005 » Make your WebSite secure from unauthorised or unauthenticated Users

Make your WebSite secure from unauthorised or unauthenticated Users

In this article I am going to explain that how we can make our site secure from unauthorised access. How we can restrict those user which want to access the pages of the sites without Login?

Author Rank :
Page Views : 23243
Downloads : 0
Rating :
 Rate it
Level : Beginner
   Print Read/Post comments Post a comment  Similar Articles  
   Email to a friend  Bookmark  Author's other articles  
 
6 Months Free & No Setup Fees ASP.NET Hosting!
Become a Sponsor
Become a Sponsor
 Tag Cloud
 Latest Jobs
More ... 
 Latest Interview Questions
More ... 

How we can make a secure Website in which unauthorized or unauthenticated user can not access the pages of site. Mean if any user wants to visit the any page by passing the URL of that page without Login then he/she should not be allowed to do this.
 

Security is to protect the pages of the any application to access by the unauthorized or unauthenticated user. 

 

Types of Security

  • Window Based Security
  • Form Based Security
  • Encrypting Data over the Network
  • Passport Security 

Window Based Security

 

It's the default security. It uses the window authentication mode.

 

Form Based Security

 

In this we secure the individual pages for the unauthorized access. In which we use authorization and authentication mode.

 

Encrypted Data over the Network

In this we can store our important data in the form of the encrypted data over the network.

 

Here in this article I am going to explain Form Based Security

 

Form based security realized on the Browser cookie. Any user can't be access the page of root directory unless he/she has the proper authentication ticket/token store in the cookie.

In form based security we can store the user name and password in a Database table, in Web.config file or in XML file.

 

Adding a Default.aspx

 

Add a Default.aspx into the root directory. This is the page on which the user will be redirected after entering the valid Userid and password.

 

Making the application

 

Now there are two pages in my application one page Default.aspx and second page Webpage.aspx. When I will run the application then this Webpage.aspx will come because in web.config file in LoginUrl I gave the name of this Webpage. After successfully login from here it will redirect to Default.aspx. If any user wants to access the directly this Default.aspx by passing the URL of this Default.aspx then he/she will redirect to Login page. For this I used authentication and authorization in web.config file.

 

The Web.config file will be like as:

<authentication mode="Forms">

       <forms loginUrl="Webpage.aspx"

                 cookiepath="/"

                 timeout="20"

                 Protection="All">

        </forms>       

</authentication>

  
<
authorization>

      <allow users="?"/>

</authorization>

 

Code for Webpage.aspx

 

<%@ Page Language="C#" AutoEventWireup="true"   CodeFile="WebForm1.aspx.cs" Inherits="_Default" %>

<! DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

< html xmlns=" http://www.w3.org/1999/xhtml" >

< head runat="server">

    <title>Login Page</title >

</ head>

< body>

    <form id="form1" runat ="server">

    <div>

       <table cellpadding="0" cellspacing ="0" border="4" width="40%" align="center">

            <tr><td bordercolor ="white"> &nbsp;</td></tr >

           

            <tr><td align ="center" bordercolor="white">

               <asp:Label ID="lblUserId" runat="server" Text="Enter User ID" Width="150px">

               </asp:Label>

               <asp:TextBox ID ="txtuid" runat="server" >

               </asp:TextBox>

             </td></tr>

            

             <tr><td bordercolor ="white"> &nbsp;</td></tr >

   

            <tr><td align ="center" bordercolor="white">

                <asp:Label ID ="lblpassword" runat="server" Text="Enter Password" Width="150px">

                </asp:Label>

                <asp:TextBox ID ="txtpass" runat="server">

               </asp:TextBox>

             </td></tr>

   

              <tr><td bordercolor ="white"> &nbsp;</td></tr >

              

              <tr><td align ="center" height="40px">

                 <asp:Button ID ="btnsubmit" runat="server" Text="Login" Width="130px" OnClick="Login_Click" />

                 </td></tr>

        

            </table>

        </div>

     </form>

</ body>

</ html>

The screen will become after running :



Figure 1.
 

Code for Webpage.aspx.cs

using System;

using System.Data;

using System.Configuration;

using System.Web;

using System.Web.Security;

using System.Web.UI;

using System.Web.UI.WebControls;

using System.Web.UI.WebControls.WebParts;

using System.Web.UI.HtmlControls;

 

public partial class _Default : System.Web.UI.Page

{

    protected void Login_Click(object sender, EventArgs e)

    {

        if (txtuid.Text == "Rahul" && txtpass.Text == "Delhi")

        {

            FormsAuthentication.RedirectFromLoginPage(txtuid.Text, false);
           // If we pass here True the here it will be persistent cookie

        }

        else

        {

            Response.Write("Invalid User");

        }

    }

}

On clicking Login button after entering right user name and password this will redirect to Default.aspx. If any user  want to access this default or any other page of the site without login then he/she will be redirected to this login page. After login he/she will redirect to that page which he/she want to access.

 

On Default page I used a label which text is showing that it is a Default page.  

Comment Request!
Thank you for reading this post. Please post your feedback, question, or comments about this post Here.
Login to add your contents and source code to this article
 [Top] Rate this article
 
 About the author
 
Rahul Kumar Saxena
Rahul shows great interests in working with Microsoft technologies. He specializes in the implementation of DataBase & Graphics. His area of expertise includes: C#, ASP.NET,ADO.NET,Windows Forms & Web Services. He hails from background , Master's in Computer Application. With programming he loves photography, traveling and reading books.
(Talabpur*)
Looking for C# Consulting?
C# Consulting is founded in 2002 by the founders of C# Corner. Unlike a traditional consulting company, our consultants are well-known experts in .NET and many of them are MVPs, authors, and trainers. We specialize in Microsoft .NET development and utilize Agile Development and Extreme Programming practices to provide fast pace quick turnaround results. Our software development model is a mix of Agile Development, traditional SDLC, and Waterfall models.
Click here to learn more about C# Consulting.
 
Introducing MaxV - one click. infinite control. Hyper-V Hosting from MaximumASP.
Finally – a virtual platform that delivers next-generation Windows Server 2008 Hyper-V virtualization technology from a managed hosting partner you can truly depend on. Visit www.maximumasp.com/max for a FREE 30 day trial. Hurry offer ends soon. Climb aboard the MaxV platform and take advantage of High Availability, Intelligent Monitoring, Recurrent Backups, and Scalability – with no hassle or hidden fees. As a managed hosting partner focused solely on Microsoft technologies since 2000, MaximumASP is uniquely qualified to provide the superior support that our business is built on. Unparalleled expertise with Microsoft technologies lead to working directly with Microsoft as first to offer IIS 7 and SQL 2008 betas in a hosted environment; partnering in the Go Live Program for Hyper-V; and product co-launches built on WS 2008 with Hyper-V technology.
Dynamic PDF
ceTE software specializes in components for dynamic PDF generation and manipulation. The DynamicPDF™ product line allows you to dynamically generate PDF documents, merge PDF documents and new content to existing PDF documents from within your applications.
Nevron Chart for .NET 2010.1 Now Available
The leading .NET charting control now features PDF, Flash and Silverlight export, visualization of large datasets and more. Deliver true charting functionality to your BI, Scorecard, Presentation or Scientific apps. Download evaluation now.
ASP.NET 4 Hosting
Get 2 Months Free of ASP.NET Hosting for Only $4.95/month! Receive FREE MS SQL and MySQL Databases Including ASP.NET 4/3.5, MVC 3.0, Silverlight 4, Windows 2008/IIS 7.0 Plus FREE IIS 7 Modules. Host UNLIMITED ASP.NET Web Sites – Click Here!
 
 Post a Feedback, Comment, or Question about this article
Subject:
Comment:
6 Months Free & No Setup Fees ASP.NET Hosting!
Become a Sponsor
 Comments
security by zahra On October 27, 2007
i want to make my site secure in terms of coding .i dnt want to see my coding by visitors. as any body can look up to it by right clicking and selecting source.
Reply | Email | Modify 
6 Months Free & No Setup Fees ASP.NET Hosting!
 © 2012  contents copyright of their authors. Rest everything copyright Mindcracker. All rights reserved.