Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityCommunity Membe...Community Membe...Any PowerDNN users? Any PowerDNN users?
Previous
 
Next
New Post
5/21/2008 4:43 PM
 

I am not disappointed with the response of the DotNetNuke team. I don't see what else they could have done in this situation.

I can think of a number of things PowerDNN could have done.

 


Chris
 
New Post
5/21/2008 4:45 PM
 

Dan Duda wrote

I'd also prefer that my hoster not alter any of my site files especially without my permission. If they were the only ones that knew about it they should have first contacted DNN to provide a patch and then the patch could have been offered to users through normal channels. I'd rather make changes/patches to my site myself.

 

I strongly agree with this..How dare some touch my files without my permission!!

Is this legal?

 
New Post
5/21/2008 4:50 PM
 

I have now called Tony Valenti by telephone and had a brief conversation. He explained the nature of the vulnerability and until I receive more specific details which allow me to reproduce the exploit, I do not want to comment on severity. One thing which Tony did indicate is that the exploit does not allow an anonymous user to execute ARBITRARY SQL script or modify the web.config in an ARBITRARY manner. This is an extremely important detail which was missing from the previous information released by PowerDNN. Tony has promised to send full details of the exploit to security@dotnetnuke.com . I will let you know when we receive it.


My comments are my own and are offered WITHOUT PREJUDICE

Shaun Walker
http://www.siliqon.com
 
New Post
5/21/2008 4:51 PM
 

With regards to Tony saying he doesn't have our phone numbers, they are listed on the "Contact" page of the DotNetNuke.com site.  As well, Shaun's direct line has not changed since the days of DNN 1.0.9. 

 
New Post
5/21/2008 4:51 PM
 

Hi All,

I am not a community individual, but a business individual.  The fact of the matter is that DotNetNuke is OpenSource and donates a product to a community of individuals.  PowerDNN is a business centric company.  What you people don't understand, is that as a business owner, I only care about business continuity.  The fact that I don't have to worry about the security of my site while hosted at PowerDNN is priceless.

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityCommunity Membe...Community Membe...Any PowerDNN users? Any PowerDNN users?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out