Another Least Privilege Site
Entitled, appropriately enough, https://www.leastprivilege.com/.
Some good posts:
- A link to some good info on ASP.NET 2.0 configuration from local guru K. Scott Allen (who, I should note, will likely be speaking again at our upcoming Security Code Camp).
- A sample ASP.NET 2.0 Membership Provider that uses the <credentials> section of web.config for storing credentials.