Wednesday, July 16, 2014

Powershell -Internet Explorer Web Automation

$ie = New-Object -com "InternetExplorer.Application"
$ie.Navigate("https://www.google.se/?gfe_rd=cr&ei=TDPGU7PmGofK8geauYCoDg")
$ie.visible = $true
do { sleep 5 }
while ( $ie.busy )
$doc = $ie.document
$search = $doc.getElementById("gbqfqwb")
$search.value = "yourUserName"


 

$doc.getElementById("gbqfba").click();
$ie.Quit();

Hot picks for SEO

To improve site ranking and better SEO.. using following tips:-
  1. robots.txt Block and Allow pages
  2. sitemap- Parameter Driven URLS-Help spider and web Crawler know your webpage hence better indexing.
  3. nofollow
  4. 301 redirect vs 302 redirect
  5. Canonicalization
  6. Footer Links
  7. Images with Alt attribute hmmm
  8. Html Headings (H1-h6)
  9. Title Tag
  10. Meta Keywords
  11. Meta Descriptions 
Where to start:-
 
Book Reference:
Search Engine Optimization (SEO) Secrets

Monday, July 14, 2014

How do I manage website Traffic?

Its a search engine web crawler that most optimistically keep reading resources from our website in form content information. This way it adds up to server load w.r.t to actual regular users. Hence sometimes there is additional load on server due to search engine keeps requesting information.
We can smartly manage or load balanced these traffic with good use of robot.txt, sitemaps and bandwidth throttling.

By using above set of module we can channelized the given traffic and keep updated or educated search engine about our site resources for better search and right information.

To prevent bots from reading unnecessary contents are as follows:-
  1. Images, JavaScript, CSS, layout file
  2. Registration page.
  3. Search Results
  4. .zip,.avi,.docx,.pptx and so on
  5. Pages- that needs- authentication and authorization.
Some examples; user-agent can be browser, search engine..

Disallow access to Images

User-agent: *
Disallow: /images/

Exclude Google Image Search

User-agent: Googlebot-Image
Disallow: /



Why Site Maps for SEO Search Engine Optimization?

Site maps by definitions are list of all URLS that exists for the given sites. It is an XML file that gives information about URLs content last modified, relative priorities and frequency at which content changes. Search Engine Optimizer- SEO can read this site maps based on the information provided it revisits sites and help in ranking of web pages and urls.
With this even we can help SEO instruct not to visit or read URLs if content of particular page has never undergone change.
Site specifications can be found online http://www.sitemaps.org/
Protocol:


<url set xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">

   <url>

     <loc>http://www.example.com/


      <lastmod>2005-01-01       <changefreq>monthly     <priorit>0.8





There are tools online that generates sitemaps for you.

There are two ways to submit the sitemaps to Search Engine.
1. We can use Robot.txt where we can references site maps as given below. In this way search engine web crawler can read about sitemaps in robot.txt file
sitemap: http://www.worldisnotenough/sitemaps/sitemap.xml.gz

2. We can directly feed our site maps into search engine. such e.g is webmaster tools for google search engine.

Thursday, July 10, 2014

IIS8.0 Asp.net Warmup

    AddRoleFeature
  1. Introduction
  2. Prerequisites
  3. Create Your Warmup Script Assembly
  4. Application Pool: Demo Website
  5. IIS Web Server: Configuration Editor
  6. system.applicationHost/applicationPools
  7. system.applicationHost/ServiceAutoStartProviders
  8. system.applicationHost/Sites
  9. Application Initialization
  10. Final Step: Now Run this animal
  11. Reference

Introduction

I've been working on IIS asp.net warm up thing for quite sometime and I tried all possible ways to get my warm up script working but it failed to initialized and auto start. After spending some time understanding some of the flow and internal mechanism of request flow, we able to crack the solution. This article will somewhat help you find the resolution to most common problem that we may have to tackle when enabling warmp script in IIS. I started looking few articles around IIS7.5 and auto start app pool but hardly find the resource online to give me crisp and clear steps to enable this.The overall intent of this article is to provide the end to end steps and some known issues that one would run into.There is sample demo code one can download to setup warmup thing for your website. I haven't gone to extend to explain why we need IIS asp.net warmup however I covered the most likely configuration settings that would go into running the warm up script.

Prerequisites

The Application Initialization feature requires IIS 8.0 to be installed. In addition, the Application Initialization feature within the IIS "Application Development" sub-feature needs to be installed. The following screen shot from the Windows Server 2012 Server Manager UI shows the Application Initialization feature. IIS 8.0 Application Initialization Setup Key Note: Restart server to effect above changes. This initialization plays important role when we have to execute any startup page automatically without users access any web pages. Sometimes warmp up fails to start because there is some setting that needs to be enabled under [code] applicationInitialization[/code]



Create Your Warmup Script Assembly



This warmp script will be executed at the start up of IIS app pool recylce or at time of website initialization. There can be various scenario we can embed in this start up script.Like we can have warm up script for Caching web pages or getting ready canned reports or any heavy task which takes longer time to load.For demo purpose I kept the code setup simple, to just create folder + file. Remember never have such filesystem read write operation withing website virtual directory or website directory it results in application app pool recycle everytime the filewrite operation takes place.

Application Pool: Demo Website

Enable Start Mode="Always running" from OnDemand Mode


IIS Web Server: Configuration Editor

Go to Main Application IIS Root. select Configuration Editor. Changing applicationhost.config is much safer through configuration editor than doing it manually.

system.applicationHost/applicationPools

Click on collection to proceed. Ensure highlighted property are set as given below in the screenshot.

Check AutoStart mode=true

Check StartMode mode=AlwaysRunning

system.applicationHost/ServiceAutoStartProviders

Click on collection to proceed. Ensure highlighted property are set as given below in the screenshot.


Add Assembly and class reference warmup script pacakage in ApplicationHost.config ServiceAutoStartProviders tag. We've indicated this provider with name say PreWarmUpMyCache- Mind it- MY. Next we need to provide this reference to site tag in configuration as next step. Remember type=Assembly Full Name.ClassName,Assembly Full Name


system.applicationHost/Sites

Click on collection to proceed. Ensure highlighted property are set as given below in the screenshot.
Set ServerAutoStart=true

Set preLoadEnabled=true
Set serviceAutoStartEnabled=true
Set serviceAutoStartProvider=PreWarmUpMyCache





Application Initialization

Troubleshooting 1:Ensure your assembly is compiled and exists in bin folder of website.
Troubleshooting 2:Worst case even if warmup script not called ,try including default web page access auto initialize.Refer screenshot.

Final Step: Now Run this animal

Sample Code is attached for demo purpose. Download it and apply above setting to test run the demo.

References

IIS Auto Start Warm up By Scott Guthrie IIS Tech net


Wednesday, July 9, 2014

Concurrency Visualizer for Visual Studio 2013

If you're very much into asynchronous code execution and extensively using task parallel library. You much download this VS 2013 Add on.

http://visualstudiogallery.msdn.microsoft.com/24b56e51-fcc2-423f-b811-f16f3fa3af7a

C# Code Tips: Custom Iterator- Yield and Ienumerable

// A generic method to transform one sequence into another:
delegate Tout Action(Tin element);



IEnumerable Transform(IEnumerable list, Action method)

{
foreach (Tin entry in list)

yield return method(entry);



}


public IEnumerable<string> GetCustomerDetails()



{

var customerList =GetCustomerList();
return Transformstring>(customerList,

delegate(Customer item)



{
return CreateCustomerReport(item.CustomerID, item.CustomerName, item.CustomerAddress);



});

}

HttpClient Vs WebClient- WebRequest /WebResponse

Its a bit of discussion as to use what ,when and how.


WebClient- Old .net framework

Most recently I used webrequest and Webresponse to read content of web pages like this.

 

using System.Net.Web


WebRequest request = WebRequest.Create(http://localhost/demosite);

// If required by the server, set the credentials.

request.Credentials = CredentialCache.DefaultCredentials;

// Get the response.

WebResponse response = request.GetResponse();

// Get the stream containing content returned by the server.

Stream dataStream = response.GetResponseStream();

// Open the stream using a StreamReader for easy access.

StreamReader reader = new StreamReader(dataStream);

// Read the content.

string webResponseStream= reader.ReadToEnd();

reader.Close();

HttpClient: .net 4.5 more aligned to http web api.

using System.Net.Http;
Msdn  : Provides a base class for sending HTTP requests and receiving HTTP responses from a resource identified by a URI.
 
 
One can initiate request related to GET, POST, PUT method using httpClient.
Example:http://www.dotnetperls.com/httpclient

static async void DownloadPageAsync()
    {
// ... Target page. string page = "http://en.wikipedia.org/"; // ... Use HttpClient.
using (HttpClient client = new HttpClient())
using (HttpResponseMessage response = await client.GetAsync(page))
using (HttpContent content = response.Content)
{
    // ... Read the string.
    string result = await content.ReadAsStringAsync();

    // ... Display the result.
    if (result != null &&
result.Length >= 50)
    {
Console.WriteLine(result.Substring(0, 50) + "...");
    }

Comparison
http://blogs.k10world.com/technology/webclient-httpclient-consume-http-requests/


           


 
 





 
 

 

Tuesday, July 8, 2014

My Guru - s


My Gurus!

I’ve grown in technologies seeing these people and learnt the way these folks lead the technology dimension. I owe most of my learning and way of technology only because of these set of people. I look upon them and try to shape up my career throughout these years. Indeed they’re the Pioneer and I follow them, their work and try to mark my level somewhat to their caliber. In a sense they’re inspirational to me at the same time they help me keep moving when I feel there is not much left to learn.

1.       Scott Allen – Forum ODE

2.       Scott Hanselman

3.       Phill Haack

4.       Scott Gutrie

5.       Martin Flower

6.       Rick Anderson

7.       John Galloway

8.       Maoni stephens

9.       Tezz Fernandez


11.   Bill Wagner

Security Consideration Asp.net MVC4


Bible Links of Asp.net MVC 4
http://msdn.microsoft.com/en-us/library/gg416514(v=vs.108).aspx


****Security Specific Applicable to MVC4
1. Safegaurd Controller and Action

  • AllowAnonymous
  • Authorize
  • RequireHttpsAttribute
If you want to apply Authorize attribute to all actions of the controller then use this

[Authorize]
public static void RegisterGlobalFilters(GlobalFilterCollection filters)
{
    filters.Add(new HandleErrorAttribute());
    filters.Add(new System.Web.Mvc.AuthorizeAttribute());
}

Secure using Https: RequireHttpsAttribute

public static void RegisterGlobalFilters(GlobalFilterCollection filters)
{
    filters.Add(new HandleErrorAttribute());
    filters.Add(new System.Web.Mvc.AuthorizeAttribute());
    filters.Add(new RequireHttpsAttribute());
}

http://blogs.msdn.com/b/rickandy/archive/2012/03/23/securing-your-asp-net-mvc-4-app-and-the-new-allowanonymous-attribute.aspx

2. MVC Cross Site Request Forgery- Html.AntiForgeryToken() and ValidateAntiForgeryToken

  • CSRF
  • Html.AntiForgeryToken()
  • ValidateAntiForgeryToken
  • Salt base Html.AntiForgeryToken("SaltValue")
Using Salt with AntiForgeryToken() : To support multiple form independent from each other. A kind of isolation on AntiForgeryTokem()
Two way handshaking-ValidateAntiForgeryToken at action -controller level
http://blog.stevensanderson.com/2008/09/01/prevent-cross-site-request-forgery-csrf-using-aspnet-mvcs-antiforgerytoken-helper/


3 Preventing Javascript Injection Attack/cross-site scripting, or XSS attacks ASP.NET

HTML Encode
<%=Html.Encode(feedback.Message)%>

one can inject such javascript code in feedback text area . We can prevent this using Html.Encode
http://www.asp.net/mvc/tutorials/older-versions/security/preventing-javascript-injection-attacks-vb
AntiXss library
@Encoder.JavaScriptEncode
Javascript encoding Helper class
@Ajax.JavaScriptStringEncode
http://weblogs.asp.net/jongalloway//preventing-javascript-encoding-xss-attacks-in-asp-net-mvc

Sunday, July 6, 2014

Most Common Heard Security Terminology.

Some Security Break Terminology
  • Script Kiddie- Creates malware code from copying others set of malware.
  • Spoofing
  • Social Engineering
  • Trojon Horse
  • Virus
  • Zero Day Exploit
  • Threat/Vulnerability
  • RootKit
  • Reverse Engineering
  • Router/Hub/Switch
  • Phishing
  • Leetspeek: http://en.wikipedia.org/wiki/Leet Leet (or "1337"), also known as eleet or leetspeak.The term leet is derived from the word elite.
  • Intrusion Detection System
  • Information Disclosure
  • Policy violation
  • Hijacking/hacker
  • Firewall
  • Ethical or white hat hacker
  • Escalation of privilege
  • Cracker/Cracking
  • Daemon
  • Pirated
  • Access Control List
  • Attack
  • Backdoor Enteries.
RootKit: Malicious software gain admin access, maintain same privilege access to the system , installed and behave the same way as normal system.

Zero Day Exploit: A known error, fault that developer fail to fix as there is zero day to do so. Hence the software is release until the hacker exploits it.

Worms, Virus, Trojan and bots:  Types of Malware-Malicious code
Trojan are tricks users to installed malware using social engineering. Most common is email, internet and user interaction such as popup window.

Bots- Are termed from Robot-Automated malware.

http://www.cisco.com/web/about/security/intelligence/virus-worm-diffs.html


 

Wednesday, July 2, 2014

Few Quick Walkthrough on How to work with Selenium

Download Selenium tool for Firefox IDE.
http://docs.seleniumhq.org/download/

Once you install Selenium it will appear as small SE icon in web browser. Check the image.
One can record the web flow scenario as per test case and generate code out of it. These code can be used for custom automation test for regression test or integrated or product test.



 
Sample Generated Code file.
namespace SeleniumTests
 
 
{
 
[TestFixture]
public class Code
 
 
{
 
private IWebDriver driver;
private StringBuilder verificationErrors;
private string baseURL;
private bool acceptNextAlert = true;
[SetUp]
public void SetupTest()
 
 
{
 
driver = new FirefoxDriver();
baseURL = "https://www.google.se/";
verificationErrors = new StringBuilder();
 
 
}
 
[TearDown]
public void TeardownTest()
 
 
{
 
try
 
 
{
driver.Quit();
}
 
catch (Exception)
 
 
{
 
// Ignore errors if unable to close the browser
 
 
}
 
Assert.AreEqual("", verificationErrors.ToString());
 
 
}
 
[Test]
public void TheCodeTest()
 
 
{
 
driver.Navigate().GoToUrl(baseURL + "/?gfe_rd=cr&ei=D7CzU9buL-bJ8gfYr4HQDw&gws_rd=ssl#q=Fifa+world+cup");
driver.FindElement(By.Id("gbqfb")).Click();
 
 
}