Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Performance and...Performance and...Support for External IP Security Scan ResultsSupport for External IP Security Scan Results
Previous
 
Next
New Post
5/11/2016 4:08 AM
 
Richard Howells wrote:
Without some context I don't see how you can take the scan results seriously.

For example - It states positively that this web site is running phpCMS. You are able to tell us that there is no php in sight. If it's so far wrong that it positively identifies the wrong product why would we take any of its output seriously?

If you are under management pressure - ie they have paid for this scan and therefore are motivated to believe it - you will have to gather more information. For example it's not very useful to state that the site as a whole suffers from a problem. There can be site wide problems but if you have to attack this you'll need to start off with a specific page; a specific example of the test input; and a far more precise statement of why the result is wrong/bad/broken.

Richard, thanks for the reply.

We had a professional scan done on a number of our external IP address as well as this one and a lot of the issues which were in the "high" category I was able to re-mediate, for example this website (acuigen.com/IP address) was showing unnecessary HTTP response headers.

I am not trying to say that either the scan nor anyone here is falsely identifying anything, as *from my limited knowledge* we haven't used any php for the site. HOWEVER we are using some 3rd party plugins/modules which may be causing this issue *again I don't know*. I can have a look into the files on the web server if need be.

For the skin we are using this template here: http://demo7.dnngo.net/20047/en-us/home.aspx
For our blog we are using this: 
http://www.dnngo.net/OurModules/xBlog.aspx

These 4 I've put in here are ones which I don't really have much experience about and even from google searching I didn't get a great idea of what they were caused by or how to fix them, apologies if I've come off as someone just complaining about problems which aren't in-fact to do with DNN.

 
New Post
5/11/2016 4:14 AM
 
Sebastian Leupold wrote:
4 is not of relevance,
3 is false identification
2 is not applicable IMO
1 is not applicable, as DNN doesn't use CGI scripts

Hi Sebastian, thanks for the simple responses.

Could you explain number 3 being a false identification please? Is it because "phpCMS" has nothing to do with DNN? Could it be a 3rd party DNN module/plugin we're using?

For 1, what are "CGI scripts"? could they also have something to do with a 3rd party DNN plugin?

I think it'll help to contact the supplier for the 3rd party plugins/modules which we're using for the skin and blog.

 
New Post
5/11/2016 4:47 AM
 
non of the DNN platform or extensions (as far as I know) are using PHP, as PHP requires a different technology stack (DNN is using IIS, C#/VB.Net and ASP.NET with SQL Server).
Unless you install phpCMS in a virtual subdirectory, this is a false detection.

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Performance and...Performance and...Support for External IP Security Scan ResultsSupport for External IP Security Scan Results


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out