Skip to main content

How To Prevent BREACH Attack in ASP.NET MVC 5 Apps?

BREACH attack -
1.     Disabling HTTP compression
2.     Separating secrets from user input
3.     Randomizing secrets per request
4.     Masking secrets (effectively randomizing by XORing with a random secret per request)
5.     Protecting vulnerable pages with CSRF
6.     Length hiding (by adding random number of bytes to the responses)
7.     Rate-limiting the requests
This is reported by this tool - https://acunetix.com/

How To Prevent BREACH attacks in ASP.NET MVC 5 Apps? How do we implement them?
The Points will need to be Implements to Prevent the BREACH Attacks -
1.     Implement the CSRF attacks on every form.
2.     Encrypt all sensitive information within the response body.
3.     Disabling HTTP compression in IIS and the BREACH ATTACH issue was no longer raise by our security scans by acunetix.com

How To Disabling HTTP compression?

Disabling HTTP Compression - Windows 8 or Windows 8.1
The Steps Are -
1.     Go to Start => Control Panel
2.     Control Panel => Programs and Features and click on Turn Windows features on or off
3.     Expand Internet Information Services
4.     Expand World Wide Web Services
5.     Expand Performance Features
6.     Select Dynamic Content Compression and Static Content Compression
7.     Ok
8.     Close

Disabling HTTP compression - Windows Server 2012 or Windows Server 2012 R2
The Steps Are -
1.     GO to Server Manager
2.     Click the Manage menu
3.     Click Add Roles and Features
4.     Add Roles and Features wizard
5.     Click to Next button
6.     Select the installation type
7.     Click to Next button
8.     Select the destination server
9.     Click to Next button
10.  Server Roles
11.  Expand Web Server (IIS)
12.  Expand Web Server
13.  Expand Performance
14.  Select Static Content Compression and Dynamic Content Compression
15.  Click to Next button
16.  Select features
17.  Click Next button
18.  Confirm installation selections
19.  Click to Install
20.  Close

How To Enable or Disable Static and Dynamic Compression for a site or application?
The steps to enable or disable static and dynamic compression for a site -
1.     Open Internet Information Services (IIS) Manager
2.     Go to IIS application directory and select the site for enable or disable compression
3.     Go to Home
4.     Go to Compression and double click
5.     Check the check-boxes to enable static and dynamic compression or remove the compression.
6.     Once you have completed the above steps, click Apply in the actions pane.
References -  

I hope you are enjoying with this post! Please share with you friends. Thank you!
By Anil Singh | Rating of this article (*****)

Popular posts from this blog

nullinjectorerror no provider for httpclient angular 17

In Angular 17 where the standalone true option is set by default, the app.config.ts file is generated in src/app/ and provideHttpClient(). We can be added to the list of providers in app.config.ts Step 1:   To provide HttpClient in a standalone app we could do this in the app.config.ts file, app.config.ts: import { ApplicationConfig } from '@angular/core'; import { provideRouter } from '@angular/router'; import { routes } from './app.routes'; import { provideClientHydration } from '@angular/platform-browser'; //This (provideHttpClient) will help us to resolve the issue  import {provideHttpClient} from '@angular/common/http'; export const appConfig: ApplicationConfig = {   providers: [ provideRouter(routes),  provideClientHydration(), provideHttpClient ()      ] }; The appConfig const is used in the main.ts file, see the code, main.ts : import { bootstrapApplication } from '@angular/platform-browser'; import { appConfig } from ...

Why doesn't App Module exist in Angular 17?

Today, I just started exploring Angular version 17 using ng new and found a problem for the newly created project using the command - ng new. The problem is: Path "/src/app/app.module.ts" does not exist while doing ng add in the Angular project. The ‘ng new’ does not generate app.module.ts in the src root folder Angular CLI 17.0.0. From Angular 17 onwards, standalone is now the new default for the CLI . So when we create a new project ‘ app.module.ts ’ file will not create Path " /src/app/app.module.ts ". Run the following command to create the new project including the file ‘app.module.ts’ in your project: ng new AngularMap  --no-standalone Note: Here ‘AngularMap’ is the project name I created. Standalone components are a feature introduced in Angular version 14. Now the changes applied in angular 17 default, the Angular team strongly recommends using them as they are easier to use, and understand.

25 Best Vue.js 2 Interview Questions and Answers

What Is Vue.js? The Vue.js is a progressive JavaScript framework and used to building the interactive user interfaces and also it’s focused on the view layer only (front end). The Vue.js is easy to integrate with other libraries and others existing projects. Vue.js is very popular for Single Page Applications developments. The Vue.js is lighter, smaller in size and so faster. It also supports the MVVM ( Model-View-ViewModel ) pattern. The Vue.js is supporting to multiple Components and libraries like - ü   Tables and data grids ü   Notifications ü   Loader ü   Calendar ü   Display time, date and age ü   Progress Bar ü   Tooltip ü   Overlay ü   Icons ü   Menu ü   Charts ü   Map ü   Pdf viewer ü   And so on The Vue.js was developed by “ Evan You ”, an Ex Google software engineer. The latest version is Vue.js 2. The Vue.js 2 is very similar to Angular because Evan ...

List of Countries, Nationalities and their Code In Excel File

Download JSON file for this List - Click on JSON file    Countries List, Nationalities and Code Excel ID Country Country Code Nationality Person 1 UNITED KINGDOM GB British a Briton 2 ARGENTINA AR Argentinian an Argentinian 3 AUSTRALIA AU Australian an Australian 4 BAHAMAS BS Bahamian a Bahamian 5 BELGIUM BE Belgian a Belgian 6 BRAZIL BR Brazilian a Brazilian 7 CANADA CA Canadian a Canadian 8 CHINA CN Chinese a Chinese 9 COLOMBIA CO Colombian a Colombian 10 CUBA CU Cuban a Cuban 11 DOMINICAN REPUBLIC DO Dominican a Dominican 12 ECUADOR EC Ecuadorean an Ecuadorean 13 EL SALVA...

SOLID Principle - Dependency Inversion Principle (DIP)

The SOLID Principles are the design principles that enable us to manage several software design problems. These principles provide us with ways to move from tightly coupled code to loosely coupled and encapsulated real business needs properly. Also readable, adaptable, and scalable code. The SOLID Principles  guide developers as they write readable, adaptable, and scalable code or design an application. The SOLID Principles can be applied to any OOP program. The SOLID Principles were developed by computer science instructor and author Robert C. Martin. Now, SOLID principles have also been adopted in both agile development and adaptive software development. The 5 principles of SOLID are: 1.       Single-Responsibility Principle (SRP) 2.       Open-closed principle (OCP) 3.       Liskov Substitution Principle (LSP) 4.       Interface Segregation Principle (ISP) 5.    ...