Welcome to MSDN Blogs Sign in | Join | Help

Web service security - Threats and Countermeasures - Part 3 : Message Validation

Threats

  • Message data may be malformed for malicious intentions such as injection attacks

Vulnerabilities

  • XML serialization helps validate some data types as XML data from the message is transformed into .Net data types – but this does not prevent against malicious content within a string being used for XML or SQL injection attacks etc.
  • Client side validation cannot be trusted by a service

Countermeasures

 

Published Wednesday, January 04, 2006 1:24 PM by Jason Hogg

Comment Notification

If you would like to receive an email when updates are made to this post, please register here

Subscribe to this post's comments using RSS

Comments

No Comments

Leave a Comment

(required) 
required 
(required) 
 
Page view tracker