Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Uploading images to a databaseUploading images to a database
Previous
 
Next
New Post
3/27/2009 10:45 AM
 

I just downloaded DNN and I am trying to get a better understanding of it.

Doesn't the Internet Guest Account need to be given write permissions to the folder in order for the upload to work?

Wouldn't the folder being used then be opened for attack? Couldn't someone scan the server, see that the account has write access to that folder and drop files there, then either run malicious software, or use it as a place to put illegal copies of movies, music, etc.?

I work at a university and one of the areas in my office wants to move their current blogs from an outside vendor's site to ours. They also want  to eventually add an Wiki. So DNN looked to me to be the best solution. At the most there will be 15 bloggers who on average blog about 3 times a week. So we're not looking at a really high volume of entries here. Not ever entry will include images.

I had trouble getting the system admin to give the account write access on my test server, so I know it will be a battle to do it on my production server. That is why I want to upload the files to the SQL server.  

 

 
New Post
3/27/2009 10:58 AM
 

upload is performed by the ASP.net Account ("Network Service" by default), IIS guest accounj only needs read permission.


Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
3/27/2009 12:10 PM
 

How big of a security issue is that for the server?

Could someone without access to the upload pages of the DNN get into the folder and drop files?

 
New Post
3/29/2009 6:08 AM
 

Hi Donna,

no, there's no security issue. The ASP.Net account is a privileged account, only used by the code itself, and no other user accounts should be granted write permissions to the folders in order to have DNN up and running. This being said, the DNN framework is a very robust and secure platform.

Best regards,
Dario Rossa

 
New Post
3/30/2009 2:53 PM
 

Thank you for the information!

I will let my system admin know this.

It will make implementing DNN a lot easier if I don' t have to modify modules!

 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Uploading images to a databaseUploading images to a database


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out