This is a pretty good article on some security considerations in ASP.NET applications, and how they can be addressed by editing your web.config file.