Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Is DotNetNuke.com Insecure?Is DotNetNuke.com Insecure?
Previous
 
Next
New Post
5/22/2008 12:54 PM
 

Moving past all of the excitement from yesterday, we are definitely making some progress. However, I do not want people to get the false impression that PowerDNN has learned from their mistake. Their security scanner is still online this morning, even after repeated requests from DNN Corp as well community members to take it offline. For a hosting company to publicly offer a hacking tool which puts all DotNetNuke community members at risk, is completely unprofessional. There is no question that PowerDNN offers a solid DotNetNuke hosting infrastructure. Unfortunately their recent behavior and lack of cooperation speaks volumes in terms of their business ethics. I am still hopeful that I will witness some very basic actions on the part of PowerDNN which demonstrate that they can be trusted.


My comments are my own and are offered WITHOUT PREJUDICE

Shaun Walker
http://www.siliqon.com
 
New Post
5/22/2008 12:59 PM
 

Penny Rand wrote

I'm glad to see the tone moderate a bit, really I think the speculation that Power DNN is getting rich off of this is way out there.

Well - I had been prepared to give the benefit of the doubt to PowerDNN - but this morning their - "Tool to find DNN sites to attack" is still on their site after numerous requests from the community to take it down.  This tool just highlights sites for hackers to try. 

The request to only test sites that you own is ludicrous.


Charles Nurse
Chief Architect
Evoq Content Team Lead,
DNN Corp.

Want to contribute to the Platform project? - See here
MVP (ASP.NET) and
ASPInsiders Member
View my profile on LinkedIn
 
New Post
5/22/2008 1:10 PM
 

I'm with Penny, Charles, Vitaly, and Peter.

I have dealt with PowerDNN and Tony V. for almost three years now and from my experience Tony is trustworthy and professional.

Yes, I think they made some mistakes but who on these forums have never made a mistake?

Greg

 
New Post
5/22/2008 1:23 PM
 

Here is the other thing thats interesting... We have a customer who forwarded their email and was asking about what changes were made (as we have some custom file changes that don't require a recompile but affect some other .ascx files etc...) So... I went on their server and there were no changes to any of the DLL's or files at all? In fact a comparison of our development environment and their production environment show the exact same file set, yet when I use the tool to check it shows that the site hosted on PowerDNN is not vulnerable yet the site hosted on the development environment is... So maybe it was a server change that can fix this? Either way,  I was expecting a DLL change?

So... I sent an email over to John and Tony wanting to know so I can inform our client. These types of things are necessary to make sure we have PRD environment that is not out of sync with a DEV environment. I have not heard back yet but hope to shortly.

I also agree that the scanner needs to come down, especially since it just checks the log files to see the version number. Its probably a useful tool if it emailed the administrator of the site the results and not just anyone who wanted to type in a generate a current list of every site running DNN and what version they are on. I mentioned this to John yesterday and saw a similar request from Mitchel as he CC'd me on the email, maybe something where you could specify a starting email @ and then a static domain that you are checking against.

 

-Chad

Data Springs, Inc.

DotNetNuke Modules

 

 
New Post
5/22/2008 1:26 PM
 

Leazon, it is one thing to make a mistake and take corrective action as you get more information.  But Tony, representing PowerDNN, knows very well how reckless it is to have that security tool out there in the public - to be used by the good and the bad.   He has been told outright how reckless this move is...and still, today it remains available.

And you are taking this lightly.  And I can see why.  I tracerouted to your site, and I can see that you are hosted with PowerDNN.  So, you are "patched" (well not officially, but a hacky type of patch at least).  The rest of the DotNetNuke community is at significant risk - not because of the specific vulnerability that was reported - but because this security tool puts hackers on the fast track to exploiting any old vulnerability on unpatched sites.

This is the equivelant of putting a sign on your own front door that says "I have a home alarm system, but my next door neighbor doesn't."  As the neighbor, how would that make you feel?

Dan

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Is DotNetNuke.com Insecure?Is DotNetNuke.com Insecure?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out