Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Funding: DNN and hacker safe?Funding: DNN and hacker safe?
Previous
 
Next
New Post
5/1/2008 8:16 PM
 

please report issues regarding security to our security team: 
security (at) dotnetnuke.com


Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
6/21/2008 5:43 AM
 

Hi,

Hackersafe is running fine as well on a this online tennis shop. Only what I dislike is that the event viewer gets full of notifications. Is there a way to tell the event viewer not to log for the scan

 
New Post
6/21/2008 7:39 AM
 

AFAIK all hackersafe does is run checks against known vulnerabilities, along with a few other common checks for echoed XSS strings. I suspect that they probably compile their known list of vulnerabilities from our security page @ http://www.dotnetnuke.com/News/SecurityPolicy/tabid/940/Default.aspx , or else pull it from security vulnerability sites such as securityfocus (who in turn pull most of their data from the security page on dotnetnuke). From time to time, there will be issues in 3rd party modules, sometimes incorrectly identified as dotnetnuke issues. As such it is useful to check your site and ensure that it's up to date, but in core terms, logging in as host and going to host settings and looking to see if you're up to date (the icon at the top) performs much the same function. I guess the added value from hackersafe is that it's push rather than pull i.e. they email you rather than requiring you to monitor the security rss feed on dotnentuke.com, or check for latest upgrades, as well as checking for 3rd party module issues. Additionally, adding the logo to your site does give your users a better feeling of security.

Note: the above only applies to application security (i.e. dotnetnuke) - tools such as hackersafe also check for exploits dependant on the lack of Microsoft security patches, so it is useful to ensure that your server is up to date.

J.O - I recorded an enhancement request a while back to add an exclusion IP/host list for events, so that urls' such as hackersafe or internal audits via tools such as metasploit etc., could be ran against dotnetnuke sites without logging 1000's of issues. It's not in scope for 5.0, but will probably make the next release after that.

Cathal


Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
6/21/2008 7:43 AM
 

Ben Rodden wrote

I run a payment website (www.physicianstouch.com) that used the hacker safe service.  Current the site is running on the 4.8.2 version of DNN and we have had very few problems with passing the scans.  Only one vulnerability and that was with the ErrorPage.apsx.  I believe it was a cross site scripting issue.

There are a number of security fixes in both 4.8.3 and 4.8.4, that error page vulnerability is one of them (see http://www.dotnetnuke.com/News/SecurityBulletins/Policy/Securitybulletinno9/tabid/1135/Default.aspx), I'd recommend you upgrade to 4.8.4

Cathal


Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
8/1/2008 1:20 AM
 

Hi

 I not able to add new thread it is currently unavailable, so I am try with this.
 I have the same problem.

 we had faced some cross scripting problem with version DNN 4.8.2 and we read that DNN 4.8.4 has solved that problem, so we had taken decision to upgrade to this version.

After up gradation we are using old database, is it ok? i have create version entry in version table manually, because after running my site it redirects to under construction site page.

Is it solve our cross scripting problem?

 

Thanks,

 Amruta Taralkar

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Funding: DNN and hacker safe?Funding: DNN and hacker safe?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out