Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Couple of questions from a newbieCouple of questions from a newbie
Previous
 
Next
New Post
3/20/2006 2:41 PM
 
Hey guys, its been a while since I've been around here and I can definitely see ther've been a bunch of great changes.

I have some questions though before I spend too much time. I know people don't like to openly discuss exploits but I really need to know. Have there been many reports about dnn site hackings such as sql injections and similar exploits that plague the living hell out of phpnuke? I've used phpnuke for a pretty long time now, had my site hacked many times but this last time was the last straw for me as I literally lost everything because of some lame exploit that enabled them to delete my forums, messages AND all my news articles. I realize I should have had a better backup plan then I had (or actually didn't have) but I'm not s security expert or a web programmer so I dont feel like I should have to be a guru to actually make my site secure.

Also I'm not sure what to call it but I'm wondering if DNN uses ASAPI rewrite or if you guys have just figured out how to impliment that feature without server tweaking... meaning website urls are page1/anotherthing.aspx instead of content=1&storyid=2
 
New Post
3/21/2006 6:50 PM
 

We take security very seriously and have tried to make DNN as robust as possible, utilising multiple different layers of security where possible (a "defense in depth" policy). Much of the design and architecture of DNN helps with this aim, in particular the fact that we've always embraced the use of stored procedures, which cuts down the possibility of sql injection hugely. Other common areas such as cross site scripting and viewstate tampering have also protection built into the framework (see the security blog for details on some of these areas).

Security is an ongoing task, so expect further enhancements, blog posts and documentation to help ensure we are secure as possible.

As for url rewriting, at present DNN supports the use of machine-friendly url's, where we transform the ?tabid=xx notation into a path that also uses the menu structure to build the url. In a future version,we will also support the ability to map id's to user selected paths. All of this uses httpmodules, so doesn't require the installation of any component(s) or server settings.

Cathal


Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Couple of questions from a newbieCouple of questions from a newbie


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out