On shared Windows hosting, security is split between two parties. Domain India looks after the server: Windows updates, IIS, the firewall and the Plesk installation. You look after everything your application does and every password that opens your account. Most ASP.NET sites that get compromised are broken through the second half, so this guide focuses on the steps in your hands.
Protect your logins first: a unique client-area password with two-factor authentication, and separate strong passwords for Plesk, FTP and each database user. Keep secrets out of files the web server can serve, switch off detailed errors, and use parameterised queries, output encoding and antiforgery tokens in your code. Check your NuGet packages for known vulnerabilities, send security headers, and keep your own backups alongside the weekly ones included with hosting.
1. Who secures what
- Passwords for the client area, Plesk, FTP, mailboxes and databases
- Your application code and its dependencies
- Configuration files and secrets in your account
- Your own backups before changes
- Windows Server updates and IIS configuration
- The server firewall and which ports are open
- The Plesk installation and its updates
- Server-wide application pool settings
Because the server side is managed, steps such as "configure the Windows firewall" or "install a web application firewall" are not something you do on shared hosting. If you think something at server level is wrong, open a ticket.
2. Lock down your logins
- Client area: turn on two-factor authentication. Anyone who gets into the client area can open Plesk with one click. See Enable two-factor authentication.
- Plesk: use a long, unique password. Reset it from Manage › Access › Reset password in the client area if you think it has leaked; see Reset your Plesk password.
- FTP: give each developer their own FTP account where Plesk allows it, and remove accounts that are no longer needed.
- Database users: one user per application, with a random password. Never reuse your Plesk password for a database.
- Never share passwords by email or chat. Domain India support will never ask for a password.
3. Keep secrets where the web can't read them
IIS refuses to serve web.config, and an ASP.NET Core app serves static files only from wwwroot. Risk comes from copies and wrong placement:
- never leave
web.config.bak,appsettings.json.oldor a.zipof your site inhttpdocs; - never put API keys or connection strings in JavaScript or anything under
wwwroot; - keep the production connection string in configuration on the server, not in your Git repository.
4. Switch off detailed errors
Detailed error pages show file paths, code and settings. In production:
- ASP.NET Core: run as
Production(the default when nothing is set), and useapp.UseExceptionHandler("/Error"), not the developer exception page. - .NET Framework: set
customErrorstoRemoteOnlyorOn, anddebugtofalseon thecompilationelement inweb.config. - Logs: if you turned on the ASP.NET Core stdout log to debug, turn it off again.
5. Write code that resists common attacks
| Attack | Defence in ASP.NET |
|---|---|
| SQL injection | Entity Framework or parameterised SqlCommand queries; never build SQL from user input |
| Cross-site scripting (XSS) | Razor encodes output by default; avoid Html.Raw with user data |
| Cross-site request forgery | Antiforgery tokens, added automatically to Razor forms; validate them on POST |
| Weak password storage | ASP.NET Core Identity or another proven hasher; never store plain or MD5 passwords |
| Malicious uploads | Check type and size, rename files, store them outside wwwroot where possible |
For a structured checklist, see How to use OWASP security guidelines.
6. Keep dependencies up to date
Outdated packages are a common way in. From your project folder:
dotnet list package --vulnerable --include-transitiveUpdate anything it reports, rebuild and redeploy. Keep your app on a .NET version that Microsoft still supports, and check in Plesk which versions the server offers.
7. Send security headers
Headers tell browsers to block common tricks. In web.config, inside system.webServer:
<httpProtocol>
<customHeaders>
<add name="X-Content-Type-Options" value="nosniff" />
<add name="Referrer-Policy" value="strict-origin-when-cross-origin" />
<add name="Content-Security-Policy" value="frame-ancestors 'self'" />
</customHeaders>
</httpProtocol>Add HTTPS with HSTS as described in Configuring SSL for ASP.NET sites. Test after each change: a strict Content-Security-Policy can block your own scripts. If web.config then gives a 500.19 error, remove the last section you added.
8. Watch logs and keep backups
- Logs: look at your Plesk access logs from time to time for bursts of failed logins or requests to paths you don't have, such as
/wp-login.php. See How to check Plesk logs. - Backups: backups included with Domain India shared hosting, Windows included, are weekly. Keep your own copy of files and databases before every deployment; Creating backups in Plesk shows how.
- If you are hacked: follow the security checklist for a hacked website, change every password, and open a ticket.
9. Where Domain India Windows hosting fits
Every Windows plan is managed in Plesk, with free SSL and the server side maintained by Domain India. The cards show live prices, excluding 18% GST.
- 30 GB Storage
- 150 GB Monthly Bandwidth
- 5 Websites
- 50 Email Accounts
- 100 GB Storage
- Unmetered Bandwidth
- 15 Websites
- 100 Email Accounts
ASP Enterprise lists a dedicated application pool, which keeps your app in its own worker process, separate from other customers' sites.
Do I need to configure the Windows firewall on shared hosting?
No. On Domain India shared Windows hosting the server, its firewall, IIS and Plesk are managed by Domain India. You secure your application code, configuration and passwords.
Can visitors download my web.config or appsettings.json?
IIS refuses to serve web.config, and an ASP.NET Core app serves static files only from wwwroot. The risk is renamed copies such as web.config.bak or zip files left in httpdocs, so delete them.
How do I check my ASP.NET app for vulnerable packages?
Run dotnet list package --vulnerable --include-transitive in your project folder, update the packages it reports, then rebuild and redeploy.
How do I stop SQL injection in ASP.NET?
Use Entity Framework or parameterised queries for every database call, and never build SQL strings from user input.
What should I do if my ASP.NET site is hacked?
Take a copy of the current files for investigation, change every password including Plesk, FTP and database users, restore clean code from your repository, and open a support ticket.
Are backups included with Windows hosting?
Yes. Backups included with Domain India shared hosting, Windows included, are weekly. Keep your own copies too, especially before every deployment.
Ready to run your ASP.NET app on managed Windows hosting? Compare the Windows hosting plans, or open a ticket if you suspect a security problem. Support is on 24/7 live chat, and tickets get a first response within 15 minutes.
The server, IIS and Plesk are maintained for you, so you can focus on your application.
See Windows hosting plans