Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Would you run DNN 4.4?Would you run DNN 4.4?
Previous
 
Next
New Post
4/30/2009 7:52 PM
 

My org is purchasing an ecommerce cart system that will only run on DNN 4.4. As far as i (as our webmaster) can tell it's a custom DNN module, it will not host user generated content, blogs or anything else, it will be a separate site on the same server as our main website.

The vendor of our online ticket system is insisting that they will not upgrade beyond DNN 4.4 as there have not been enough changes. But when i look at the bug tracker i see many very important security updates. I have tested a simple exploit and DNN 4.4 is indeed vulnerable to http://www.securityfocus.com/archive/1/492793 which would allow an attacker to manipulate a page and redirect the user in a phishing attack.

My advice to the org is not to put the system in to production until the vendor can assure us that we will be supported on recent and future versions of DNN 4.x.

I don't have much experience with DNN, but would never put such an out dated Drupal system in to production especially where personal data and e-commerce is involved.

Is it reasonable to expect a vendor to maintain compatibility with 4.x and is it possible to secure DNN 4.4 against all know exploits?

 
New Post
4/30/2009 8:05 PM
 

 would you going to buy today a software running on Windows 95 only?


Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
4/30/2009 8:21 PM
 

In DNN time... 4.4 is mighty old (2 years)... subject to more than half of the security advisories listed.  I would personally find it difficult to believe that an application which has not been updated for it's target platform in 2 years would be better supported in the future?  Unless, perhaps, they have chosen to wait to upgrade to version 5.1 (which is slated to go into beta next month)... but that would be a stretch.

If DNN integration is required, there are several good, well supported options out there.  If it's NOT required... there are obviously a lot more.  But as you have articulated the situation, it does not sound like the best choice.

Cheers


Scott Willhite, Co-Founder DNN

"It is only with the heart that one can see rightly... what is essential is invisible to the eye. "
~ Antoine de Saint-Exupéry

 
New Post
4/30/2009 9:12 PM
 

"Would you run 4.4 ?" No.

"Is it reasonable to expect a vendor to maintain compatibility with 4.x and is it possible to secure DNN 4.4 against all know exploits?"

Yes, vendors should maintain forwards compatibility with each new releas

Yes, it is possible to secure 4.4 against known exploits: upgrade to 4.9.3.

Forking the DNN code base loses all the benefits of being on the DNN framework : notably continuous bug fixes, enhancements and plugging of exploits.

As stated already : if you're not going to stay on the DNN main code line, then you may as well not use it.  Either choose an e-commerce package compatible with the latest releases, or buy a non-dnn ecommerce package.  Buying one only compatible with an older version is the worst of both worlds.

 
New Post
4/30/2009 9:40 PM
 

Hi fungi,

You've got some big names in DNN answering this post, and from a less known developer in DNN I would have to say if the responsibility for the system stands with you, be very careful.  I myself have developed NB_Store (e-commerce) and one of my golden rules is to try and make sure it  can upgrade to the next release.  This is sometimes impossible, because we don't know what the next release of DNN  will bring.  But in my expreriance if the DNN module is correctly integrated into DNN then upgrades to DNN seem to be painless (Not always the case, but exceptions always break the rule).  This leads me to think 4 things about your vendor:

1 - They've tested the application within the environment it exists in and believe no threats exists. (This is possible, depending on the structure, software changes and environment)

2 - They don't want to spend any money in testing an upgrade.(Hmm!!! say no more!!)

3 - They've change the DotNetNuke core in order to deal with your specific requirements (Not a bad thing if it's been dealt with correctly, hence upgrade may not need doing because the security issue are redundant or superceeded with their changes, but this would mean continual checking and could also be the reason they don't want to upgrade!!)

4 - The developer that did the original changes has left the company and they find themselves with a lack of DNN expertise (Could be a big worry!!)

In conclusion, you need to understaand why they can't upgrade? Their answers could give you the information you need.

Best of Luck,

Dave.

 

 

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Would you run DNN 4.4?Would you run DNN 4.4?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out