Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityCommunity Membe...Community Membe...Any PowerDNN users? Any PowerDNN users?
Previous
 
Next
New Post
5/21/2008 1:41 PM
 

What the hell is going on here? Did PowerDNN discover a security vulnerability and not tell the DNN team about it?

And then charge $20 to fix it?

 


Chris
 
New Post
5/21/2008 2:02 PM
 

Seems like...

 
New Post
5/21/2008 2:11 PM
 
What is confusing is whether the DNN team has been contacted or not. Nothing should have been mailed or posted until the DNN team had a chance to review and develop a fix. If indeed there is a vulnerability someone could see this post and the PowerDNN site and begin investigating how to exploit. If it were me I’d kill this thread completely and ask PowerDNN to remove the notice on their site until a fix is widely available to the entire community. Certainly they should apply a patch to their customer sites as needed but keep this under wraps until a fix is GA for all.
 
New Post
5/21/2008 2:20 PM
 

Hi Guys,

When we discovered this vulnerability, it was found to be such a critical issue that we were compelled to secure our customers right away.  Our first responsibility is always going to be to make sure that PowerDNN customers are running high performance, secure, DNN installations.  Our customers have been overwhelmingly thankful for the hard work we've done to secure their sites.  Our team is putting together an official report which we will release to the community, it is important that everyone is aware of the issue.  We have been in contact with certain members of the core team as well as many of the top vendors in the community.  In terms of the $20, we could take that away but then we wouldn't be able to patch non-PowerDNN customers in any way that would be financially feasible.  If we got rid of the $20 charge, we could scan your site but not perform any fix.  This issue effects so many sites that we want to protect community by releasing the information in a thoughtful way.  We will get the information out via the normal DNN channels, but, we view this issue as being critical enough that waiting until the next release of DNN is not sufficient and we were compelled to take action immediately.  I hope this clears some things up for some people, we take issues like this very seriously, because like most of you, we love DotNetNuke and it is our livelyhood. 

John Grange

 
New Post
5/21/2008 2:22 PM
 

Tony Valenti wrote

Hey Dan,
We are working with the DotNetNuke Core Team to make this patch available to everyone.  We're not releasing the patch to the public as of yet because if the wrong people became aware of the flaw or its location, it would mean catastrophe for almost any non-PowerDNN customer who has set up DotNetNuke within the past year.

During this "Zero Day" time period, we are offering a service where our engineers will work with companies for virtually free to help them patch their mission critical websites while the DotNetNuke core team creates an "official" resolution to the issues.

I understand that you're really curious about what the flaw was, however, if you notice any changes, please hold back from discussing them.

Always glad to help,
-Tony Valenti

But what if malfeasants are able to come up with $20?  Are the PowerDNN engineers asking any trick questions to ensure that people buying the fix have good intensions? 

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityCommunity Membe...Community Membe...Any PowerDNN users? Any PowerDNN users?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out