Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Web Application Information DisclosureWeb Application Information Disclosure
Previous
 
Next
New Post
10/17/2012 6:56 AM
 
as far as I can see, there is no physical path displayed, all paths are virtual paths being used to pass parameters (e.g. h ttp://www .practicepointhiv.com/Home/tabid/38/ctl/Terms/Default.aspx), which do not disclose any critical information.

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
10/17/2012 7:19 AM
 

Mine clearly states the path.  Please see below.  It Points to the Css File.

IF you happen to view the code on DOTNETNUKE site, it also shows the path to the css file.

 

.0 Description: Web Application Information Disclosure Synoposis: The remote web application discloses path information. Impact: At least one web application hosted on the remote web server discloses the physical path to its directories when a malformed request is sent to it. Leaking this kind of information may help an attacker fine-tune attacks against the application and its backend. Data Received: The request GET /Home/tabid/55/ctl/SendPassword/Default.aspx?__dnnVariab le=`{`__scdoff`:`1`} HTTP/1.1\r Host: umbrella.gaborinsurance.com\r Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r Accept-Language: en\r Connection: Keep-Alive\r User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)\r Pragma: no-cache\r Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*\r \r produces the following path information :< link type="text/css" rel="stylesheet" href='/Portals/0/AllDnnSett [...]< link
 
New Post
10/17/2012 8:17 AM
 
Bump. Can anyone help?
 
New Post
10/17/2012 8:17 AM
 
a relative path on the server is not an information disclosure and paths to all css, js and image files are public, due to being downloaded directly from the server - which is not regarded as an information disclosure.

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
10/17/2012 8:27 AM
 

THank you clarity.  But I corrected all the jpg by changing the URL from portals to actual web url path for example: http://www.gaborater.com/logo.png

If Security Metrics states that it shows the path and will not comply with PCI complaince, then I still need a solution. I know that you state it is a public file, but is there a way to change the path to a URL instead of a path.  Needless to say, I am not able to comply with PCI if not this is not corrected.

 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Web Application Information DisclosureWeb Application Information Disclosure


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out