ASP.NET & .NET Development

How to Secure Your ASP.NET Applications on Plesk and Windows Server 2019

By the Domain India teamPublished 6 min read
Knowledge base article
Contents (9 sections)

On shared Windows hosting, security is split between two parties. Domain India looks after the server: Windows updates, IIS, the firewall and the Plesk installation. You look after everything your application does and every password that opens your account. Most ASP.NET sites that get compromised are broken through the second half, so this guide focuses on the steps in your hands.

Key takeaways

Protect your logins first: a unique client-area password with two-factor authentication, and separate strong passwords for Plesk, FTP and each database user. Keep secrets out of files the web server can serve, switch off detailed errors, and use parameterised queries, output encoding and antiforgery tokens in your code. Check your NuGet packages for known vulnerabilities, send security headers, and keep your own backups alongside the weekly ones included with hosting.

1. Who secures what

Your part
  • Passwords for the client area, Plesk, FTP, mailboxes and databases
  • Your application code and its dependencies
  • Configuration files and secrets in your account
  • Your own backups before changes
Domain India's part
  • Windows Server updates and IIS configuration
  • The server firewall and which ports are open
  • The Plesk installation and its updates
  • Server-wide application pool settings

Because the server side is managed, steps such as "configure the Windows firewall" or "install a web application firewall" are not something you do on shared hosting. If you think something at server level is wrong, open a ticket.

2. Lock down your logins

  • Client area: turn on two-factor authentication. Anyone who gets into the client area can open Plesk with one click. See Enable two-factor authentication.
  • Plesk: use a long, unique password. Reset it from Manage › Access › Reset password in the client area if you think it has leaked; see Reset your Plesk password.
  • FTP: give each developer their own FTP account where Plesk allows it, and remove accounts that are no longer needed.
  • Database users: one user per application, with a random password. Never reuse your Plesk password for a database.
  • Never share passwords by email or chat. Domain India support will never ask for a password.

3. Keep secrets where the web can't read them

IIS refuses to serve web.config, and an ASP.NET Core app serves static files only from wwwroot. Risk comes from copies and wrong placement:

  • never leave web.config.bak, appsettings.json.old or a .zip of your site in httpdocs;
  • never put API keys or connection strings in JavaScript or anything under wwwroot;
  • keep the production connection string in configuration on the server, not in your Git repository.

4. Switch off detailed errors

Detailed error pages show file paths, code and settings. In production:

  • ASP.NET Core: run as Production (the default when nothing is set), and use app.UseExceptionHandler("/Error"), not the developer exception page.
  • .NET Framework: set customErrors to RemoteOnly or On, and debug to false on the compilation element in web.config.
  • Logs: if you turned on the ASP.NET Core stdout log to debug, turn it off again.

5. Write code that resists common attacks

AttackDefence in ASP.NET
SQL injectionEntity Framework or parameterised SqlCommand queries; never build SQL from user input
Cross-site scripting (XSS)Razor encodes output by default; avoid Html.Raw with user data
Cross-site request forgeryAntiforgery tokens, added automatically to Razor forms; validate them on POST
Weak password storageASP.NET Core Identity or another proven hasher; never store plain or MD5 passwords
Malicious uploadsCheck type and size, rename files, store them outside wwwroot where possible

For a structured checklist, see How to use OWASP security guidelines.

6. Keep dependencies up to date

Outdated packages are a common way in. From your project folder:

bash
dotnet list package --vulnerable --include-transitive

Update anything it reports, rebuild and redeploy. Keep your app on a .NET version that Microsoft still supports, and check in Plesk which versions the server offers.

7. Send security headers

Headers tell browsers to block common tricks. In web.config, inside system.webServer:

xml
<httpProtocol>
  <customHeaders>
    <add name="X-Content-Type-Options" value="nosniff" />
    <add name="Referrer-Policy" value="strict-origin-when-cross-origin" />
    <add name="Content-Security-Policy" value="frame-ancestors 'self'" />
  </customHeaders>
</httpProtocol>

Add HTTPS with HSTS as described in Configuring SSL for ASP.NET sites. Test after each change: a strict Content-Security-Policy can block your own scripts. If web.config then gives a 500.19 error, remove the last section you added.

8. Watch logs and keep backups

  • Logs: look at your Plesk access logs from time to time for bursts of failed logins or requests to paths you don't have, such as /wp-login.php. See How to check Plesk logs.
  • Backups: backups included with Domain India shared hosting, Windows included, are weekly. Keep your own copy of files and databases before every deployment; Creating backups in Plesk shows how.
  • If you are hacked: follow the security checklist for a hacked website, change every password, and open a ticket.

9. Where Domain India Windows hosting fits

Every Windows plan is managed in Plesk, with free SSL and the server side maintained by Domain India. The cards show live prices, excluding 18% GST.

ASP Business
₹328.83/mo + GST
  • 30 GB Storage
  • 150 GB Monthly Bandwidth
  • 5 Websites
  • 50 Email Accounts
See plan details
ASP Enterprise
₹493.70/mo + GST
  • 100 GB Storage
  • Unmetered Bandwidth
  • 15 Websites
  • 100 Email Accounts
See plan details

ASP Enterprise lists a dedicated application pool, which keeps your app in its own worker process, separate from other customers' sites.

Do I need to configure the Windows firewall on shared hosting?

No. On Domain India shared Windows hosting the server, its firewall, IIS and Plesk are managed by Domain India. You secure your application code, configuration and passwords.

Can visitors download my web.config or appsettings.json?

IIS refuses to serve web.config, and an ASP.NET Core app serves static files only from wwwroot. The risk is renamed copies such as web.config.bak or zip files left in httpdocs, so delete them.

How do I check my ASP.NET app for vulnerable packages?

Run dotnet list package --vulnerable --include-transitive in your project folder, update the packages it reports, then rebuild and redeploy.

How do I stop SQL injection in ASP.NET?

Use Entity Framework or parameterised queries for every database call, and never build SQL strings from user input.

What should I do if my ASP.NET site is hacked?

Take a copy of the current files for investigation, change every password including Plesk, FTP and database users, restore clean code from your repository, and open a support ticket.

Are backups included with Windows hosting?

Yes. Backups included with Domain India shared hosting, Windows included, are weekly. Keep your own copies too, especially before every deployment.

Ready to run your ASP.NET app on managed Windows hosting? Compare the Windows hosting plans, or open a ticket if you suspect a security problem. Support is on 24/7 live chat, and tickets get a first response within 15 minutes.

Managed Windows hosting for ASP.NET

The server, IIS and Plesk are maintained for you, so you can focus on your application.

See Windows hosting plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Secure Your ASP.NET App on Plesk Windows Hosting