zoukankan      html  css  js  c++  java
  • WCF Misconfiguration: Insufficient Audit Failure Handling

    Abstract:

    The program is configured not to generate an exception when it fails to write to an audit log.

    Explanation:

    If WCF is configured not to throw an exception when it is unable to write to an audit log, the program will not be notified of the

    failure and auditing of critical security events may not occur.

    Example 1: The <behavior/> element of the WCF configuration file below instructs WCF to not notify the application when

    WCF fails to write to an audit log.

    <behaviors>

    <serviceBehaviors>

    <behavior name="NewBehavior">

    <serviceSecurityAudit auditLogLocation="Application"

    suppressAuditFailure="true"

    serviceAuthorizationAuditLevel="Success"

    messageAuthenticationAuditLevel="Success" />

    </behavior>

    </serviceBehaviors>

    </behaviors>

    Recommendations:

    Configure WCF to notify the program whenever it is unable to write to an audit log. The program should have an alternative

    notification scheme in place to alert the organization that audit trails are not being maintained.

    Web.config, line 80 (WCF Misconfiguration: Insufficient Audit Failure Handling)

    Fortify Priority: Low Folder Low

    Kingdom: Environment

    Abstract: The program is configured on line 80 of Web.config not to generate an exception

    when it fails to write to an audit log.

    Sink: Web.config:80 null()

    78 <serviceBehaviors>

    79 <behavior name="">

    80 <serviceSecurityAudit auditLogLocation="Default" suppressAuditFailure="false"

    serviceAuthorizationAuditLevel="SuccessOrFailure"

    messageAuthenticationAuditLevel="SuccessOrFailure" />

    81 <serviceThrottling maxConcurrentCalls="20" maxConcurrentSessions="20"

    maxConcurrentInstances="20" />

    82 </behavior>

  • 相关阅读:
    minicap编译示例
    uniapp H5项目中使用腾讯地图sdk
    腾讯地图打车乘客端小车平滑移动-安卓篇
    地图定位打卡功能示例
    腾讯位置服务个性化图层创建及发布
    腾讯位置服务GPS轨迹回放
    使用腾讯地图实现汽车沿轨迹行驶功能
    地图GPS轨迹录制
    腾讯地图实现微信小程序地图定位教程
    基于腾讯地图定位组件实现周边POI远近排序分布图
  • 原文地址:https://www.cnblogs.com/time-is-life/p/6203115.html
Copyright © 2011-2022 走看看