Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityCommunity Membe...Community Membe...Any PowerDNN users? Any PowerDNN users?
Previous
 
Next
New Post
5/21/2008 11:12 AM
 

Yes , I got it as I host with them.

Just out of interest I ran their security checker against my site,

it told me there were no security problems and that my DNN version was between 4.8.2 and 4.8.3

 
New Post
5/21/2008 11:35 AM
 

Hey Dan,
We are working with the DotNetNuke Core Team to make this patch available to everyone.  We're not releasing the patch to the public as of yet because if the wrong people became aware of the flaw or its location, it would mean catastrophe for almost any non-PowerDNN customer who has set up DotNetNuke within the past year.

During this "Zero Day" time period, we are offering a service where our engineers will work with companies for virtually free to help them patch their mission critical websites while the DotNetNuke core team creates an "official" resolution to the issues.

I understand that you're really curious about what the flaw was, however, if you notice any changes, please hold back from discussing them.

Always glad to help,
-Tony Valenti

 
New Post
5/21/2008 11:44 AM
 

Dan,

If you find anything can you please e-mail me at msellers@iowacomputergurus.com?  I identified an exploit that was taken on my website mitchelsellers.com last week and I have been working with the core team to identify and resolve the exploit however I have not yet been notified of a fix, the core team took me out of the loop late last week.

I also have a message in to Tony at PowerDNN to see if he can help me at all.


-Mitchel Sellers
Microsoft MVP, ASPInsider, DNN MVP
CEO/Director of Development - IowaComputerGurus Inc.
LinkedIn Profile

Visit mitchelsellers.com for my mostly DNN Blog and support forum.

Visit IowaComputerGurus.com for free DNN Modules, DNN Performance Tips, DNN Consulting Quotes, and DNN Technical Support Services
 
New Post
5/21/2008 12:25 PM
 

Hey Mitch,
Thanks for calling me.  We'll get you taken care of and I'll make sure to keep you in the loop with these two vulnerabilities.

-Tony Valenti

 

 
New Post
5/21/2008 1:25 PM
 

Please be aware that contrary to what Tony has posted above, we have NOT yet had any contact from Tony Valenti or any representative from PowerDNN on these specific security vulnerability claims. Since Tony used to be a member of our team in the past, I assume that he is aware of our Security Policy and I would have expected that he would have used proper channels to report the vulnerabilities and worked with us to ensure the DotNetNuke community was adequately protected. At this point, I am confused why PowerDNN has chosen to misreprent the facts and leverage their information as a tool to generate revenue rather than acting in good faith for the benefit of the community.

 

 


My comments are my own and are offered WITHOUT PREJUDICE

Shaun Walker
http://www.siliqon.com
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityCommunity Membe...Community Membe...Any PowerDNN users? Any PowerDNN users?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out