Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Someone accessed a protected page (security problem?)Someone accessed a protected page (security problem?)
Previous
 
Next
New Post
9/17/2008 8:18 AM
 

Hello,
in one of my portals I have a protected page (page has only view permission for a specific Role).
But in Admin --> Site Log --> detailed Site Log I see one row like this:

DateTime Name Referrer UserAgent UserHostAddress TabName 
14/09/2008 02.47.00 [blank] [blank] Netscape Navigator 6+ 74.6.22.XXX MyPageName


I'm curious to know how someone apparently anonymous (name is blank so is not logged in) has entered my protected page without logging in.   
I'm using dnn 4.8.4.
I supposed it was a search engine, but if I try to enter that page anonymously (without having logged in), I am redirect to the login page and no record is written in Logs.

How is it possible?

Bye

Luca
Italy

 

 


siti internet in provincia di cuneo torino savona asti
Siti e applicazioni Web
 
New Post
9/17/2008 11:59 AM
 

Luca:

I think you are not interpreting the Site Log properly.  That entry means that the server (or DNN) received the request for that page but it does not necessarily mean that the page was actually served to the user without login, if you setup the page to require login.  ASP.Net and DNN will automagically redirect the user to the Login dialog and then continue to display the actual requested page if the user authenticates correctly.  If the user does not login properly, the actual page is not served.

Go ahead and try it, for example, login as Admin and go the Site Settings page, copy the URL.  Logout.  Then, while logged out, paste the URL for the Site Settings page.  You should get the login dialog.  Cancel and go to main page.  Do Login again (I'm telling you to cancel and go to main page to keep the transactions separate).  Go to the Site Log report and you will see an entry for the Site Settings page without user name.  In other words, the request actually came in with the direct URL but DNN and ASP.Net handled it properly.

CORRECTION:  After keeping a doubt in my head I did the above test again and it is incorrect, when I did it the first time I was looking at the wrong line of the report, sorry.  So, back to your original question.  No there should not be an entry there for unauthenticated users, the security settings for your page may not be setup properly.  This also applies to search engines, spiders, crawlers, etc.  If you want to make sure that the page does only displays for logged-in users you have to go to page settings and make sure that you set the right for View to "Registered Users".  Hope I didn't confuse you too much.

Carlos

 

 
New Post
9/23/2008 7:22 AM
 

Carlos,
thanks for your reply.

I discovered what happened: I had 2 pages with the same name; one is public and the other is private.
In Log I saw anonimous access for the "public" one (and that's correct) confusing with the other page. 

No security problem at all for DNN!!!

Thanks

Luca
Italy

 


siti internet in provincia di cuneo torino savona asti
Siti e applicazioni Web
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Someone accessed a protected page (security problem?)Someone accessed a protected page (security problem?)


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out