Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Problems from IBM Rational AppScanProblems from IBM Rational AppScan
Previous
 
Next
New Post
5/7/2012 1:38 PM
 

I'm developing a site using DNN 6.1.5, but our IA team keeps returning a lot of errors from Rational AppScan, and since I don't actually have access to that product, I can't replicate or verify any of these. In fact, they're actively trying to do black box pen tests on my development server, so I need to harden DNN to the crazy level of secure.

The biggest problem they are seeing with their scans so far has to do with sql injections and blind sql injections. They want user input further sanitized, however, DNN has the default .net input validation disabled. Is there any way to harden against sql injections any further other than creating the dual database account trick? They also want me to "remove all shell interpreters" with many references to the print options. I'm not even sure what they're talking about here. To the best of my knowledge, this is usually in reference to CGI calls and commands,

 Thanks very much in advance!
-626

 

 
New Post
5/7/2012 3:53 PM
 

Hello,

I'd suggest you get them to email the details to security@dotnetnuke.com and our security team can analysis the results. We have had a number of AppScan reports before and all of the issues were false-positives e.g. DotNetNuke does not use direct sql or sp_exec/sp_execute so by default is not vulnerable to sql injection http://www.dotnetnuke.com/Resources/B... - obviously a 3rd party module could introduce this issue but without seeing the report results theres little you can do to guess this.


Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
5/8/2012 3:30 PM
 

Ok, thanks very much! It seems to be focusing on blind injections on the CSS modules (which the test user doesn't even have access too) and under very specific forms from the user profile edit module (user phone number for some reason). I though I was going a little crazy because I couldn't think of anything else to try aside from going though the stored procedures one at a time, line by line.

Is there a known list of false positives related to Rational AppScan and if so, is it available on the wiki? Is there any known cause or source for these false positives or is AppScan just a twitchy product? Thanks again!

 
New Post
5/10/2012 3:33 PM
 
no, we typically respond to any lists sent to us on a case-by-case basis as the tools evolve (and stop showing some false positives, and start showing new ones), and the results are different depending on the dotnetnuke version. AppScan like all automated scanners creates a huge number of false positives as it cannot deduce application logic e.g. it will often flag a simple issue (such as a cross-site scripting issue) in an area that only the host user can access - as the host user can do anything it means that the application boundary renders that issue irrelevant.

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Problems from IBM Rational AppScanProblems from IBM Rational AppScan


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out