Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Strange title on home pageStrange title on home page
Previous
 
Next
New Post
7/26/2007 12:17 PM
 

leupold wrote

this is by design

 

Can you please explain WHY this is by design? And how do you solve it?

 
New Post
7/26/2007 1:20 PM
 

let me describe a scenario - i'm a hacker who writes a simple program that uses an incremementing number to profile a site e.g. it will visit www.mysite.com/default.aspx?tabid=1 then www.mysite.com/default.aspx?tabid=2 then www.mysite.com/default.aspx?tabid=3 etc. As each page is visited the hacker doesn't have permissions so they're redirected to a login page (or tab) which is what we want. However, before the change the original pages title was preserved, so the hacker could see that tabid 1 was a page known as "About us", tabid 2 was a page known as "contact" and tabid 3 was a page known as "Password list" -this information leakage would be very handy and allow hackers to target the most "valuable" pages , so we altered the login module to not leak this information (note: this was first brought to our attention when a government client had their site failed during a security audit because of this information leakage). We could add a host level setting to allow site admins to use the old behaviour and preserve titles, but I'm not very comfortable with adding settings that allow people to reduce their security.

Cathal

 


Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
7/26/2007 1:34 PM
 

Cathal - I can understand not leaking the names of pages which the user does not have permission to visit, but why would we hide the name of the page where the login module is hosted?  If I put the login module on the homepage, a common usage scenario, why would I hide the homepage title?  There are lots of ways to achieve the goal without "taking over" a user's site.


Joe Brinkman
DNN Corp.
 
New Post
7/26/2007 1:47 PM
 

jbrinkman wrote

Cathal - I can understand not leaking the names of pages which the user does not have permission to visit, but why would we hide the name of the page where the login module is hosted?  If I put the login module on the homepage, a common usage scenario, why would I hide the homepage title?  There are lots of ways to achieve the goal without "taking over" a user's site.

I agree with this statement, I think a check could be made to see if the module ws actually placed on the tab and NOT to update the title if it is.


-Mitchel Sellers
Microsoft MVP, ASPInsider, DNN MVP
CEO/Director of Development - IowaComputerGurus Inc.
LinkedIn Profile

Visit mitchelsellers.com for my mostly DNN Blog and support forum.

Visit IowaComputerGurus.com for free DNN Modules, DNN Performance Tips, DNN Consulting Quotes, and DNN Technical Support Services
 
New Post
7/26/2007 1:50 PM
 

So what exactly is this solution to this? I have it on my homepage, and I need my homepage title for the search engines.....

 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Strange title on home pageStrange title on home page


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out