Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Is uploading skins by any user secure?Is uploading skins by any user secure?
Previous
 
Next
New Post
4/1/2008 11:16 AM
 
Hi, I want to run a dotnetnuke installation where couple of people(let's assume I don't trust them), are going create their portals. I want to allow them upload a skin through admin interface and use it. Is allowing them to upload a skin, which contains server code in ASCX files going to be secure enough? I guess it might be enough if it doesn't contain any IM A L4M3 H4X0R> tag in it. But, does the skin parsing test the skin files for it? Could anybody help me figure out how to achieve this functionality. Thanks, Chirag
 
New Post
4/1/2008 12:18 PM
 

Allowing skin uploads by untrusted users is NOT secure.  If the server is configured ocrrectly though, you can limit the damage to just their portals.  :)

Jeff

 
New Post
4/2/2008 1:11 AM
 

Hey Jeff,

Thanks for the reply. Could you elaborate more on "if the server is configured properly though, you can limit the damage to just their portals" ??

I just want to make sure that by allowing skins(ASCX) upload, I'm not exposing entire(other portals') dotnetnuke database data.

 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Is uploading skins by any user secure?Is uploading skins by any user secure?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out