views:

23

answers:

2

In the documentation for securely consuming web services with WCF they state that it is recommended that you prohibit the DTD when consuming the metadata. Why is the DTD a security risk?

http://msdn.microsoft.com/en-us/library/ms734741.aspx

+2  A: 

http://msdn.microsoft.com/en-us/magazine/ee335713.aspx

andrewbadera
+1 I like this article.
Ladislav Mrnka
:o) Thanks, I just had a friend of mine send me the same article. It is a good one.
Josh Russo
Oh you are the friend LOL
Josh Russo
A: 

In this case there is a known denial of service exploit (see andrews answer)

However, almost anything that reduces the attack surface will improve the security.

Shiraz Bhaiji