Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...AJAX Security Concerns?AJAX Security Concerns?
Previous
 
Next
New Post
7/31/2007 10:49 AM
 

I was recently sent information that suggests that there could be security concerns when using AJAX.   My company wants me to follow up on this with the DNN Community to see if we should be concerned about a large scale project we are working on using DNN.  We are using AJAX in third party modules and also developing modules using ListX and other traditional development environments.

The security information I was sent is available in the following links.

Fortify Software Documents Pervasive and Critical Vulnerability in Web 2.0

Ajax security: How to prevent exploits in five steps

I am not a developer myself, so I rely heavily on the DNN Community for answers to concerns about security.

Thanks in advance.

 
New Post
8/1/2007 10:30 AM
 

Personally I think that a big portion of this is to trust the modules that you are using and developing and to fully test those systems.

I personally have not identified any major issues with AJAX in the items I have worked with, however that doesn't mean that it doesn't exist.

I would see if Cathal has something to say on this as he is one of the big security "gurus" here.


-Mitchel Sellers
Microsoft MVP, ASPInsider, DNN MVP
CEO/Director of Development - IowaComputerGurus Inc.
LinkedIn Profile

Visit mitchelsellers.com for my mostly DNN Blog and support forum.

Visit IowaComputerGurus.com for free DNN Modules, DNN Performance Tips, DNN Consulting Quotes, and DNN Technical Support Services
 
New Post
8/1/2007 9:37 PM
 

Thanks for the reply Mitchel.

I'm not sure I would even know how to go about testing something like this.  Any idea where I would begin looking.  I've searched the forums here a little, but nothing so far.

Cathal, are you listening?

 
New Post
8/2/2007 11:30 AM
 

Yeah I am not really sure either.  I guess I really haven't heard of any major issues and I am sure that since the DNN Implementation is using the ASP.NET AJAX solution that if there were issues we would have heard....


-Mitchel Sellers
Microsoft MVP, ASPInsider, DNN MVP
CEO/Director of Development - IowaComputerGurus Inc.
LinkedIn Profile

Visit mitchelsellers.com for my mostly DNN Blog and support forum.

Visit IowaComputerGurus.com for free DNN Modules, DNN Performance Tips, DNN Consulting Quotes, and DNN Technical Support Services
 
New Post
8/3/2007 10:05 AM
 

Thanks for your input Mitchel.

Anyone else?  Surely sombody else has an opinion on this.

Calling Cathal.

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...AJAX Security Concerns?AJAX Security Concerns?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out