Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...DNN Security on NIST CVEDNN Security on NIST CVE
Previous
 
Next
New Post
3/17/2008 10:30 PM
 

I only run a few community sites on DNN but someone asked me about how secure some of the open source platforms were.  I knew that DNN was very good but I didn't have anything solid other than people just saying so.  The person asking me was interested in Drupal and Joomla in particular but CMS's in general.

So I went to the National Vulnerability Database at http://nvd.nist.gov/ to check things out.  Here's what I found when I went to the Vulnerabilities page and searched for Drupal, Joomla and DotNetNuke.

Drupal - 104 security concerns, 42 within the last year

Joomla - 213 security concerns, 125 within the last year

DotNetNuke - 7 security concerns, 0 within the last year

Looks really good, but before I "report back" to my friend, I've got a question. 

I'm not sure if the security vulnerabilities for Drupal and Joomla include all the community modules or if it is just the core.  Same with DotNetNuke.  I am not familiar with Drupal and Joomla to see if this is comparing apples to oranges.  I am hoping that someone who has looked at Drupal or Joomla would be able to recognize what components/modules/add-ons are part of the core offering (or maybe everything was core).

Anyone else want to take a look?

 
New Post
3/18/2008 6:07 AM
 

AFAIK the number stated are covering core framework with default modules only, IMO there is no chance to cover all thousands of 3rd party modules. Said this, if you are concerning about security, you should be careful in selecting additional components, I use to by modules from serious and known vendors only. 


Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
3/18/2008 7:53 AM
 

PHP applications are notorious for their security issues, however that can be mitigated by doing a proper security review, both by the development team, and the team doing an implementation.  The DotNetNuke team is fortunate to have a security team headed by Cathal Connolly that reviews our code before we ship and we have recieved a couple of reports from various security audits over the years that has allowed us to further harden DotNetNuke and the core module.  This allows us to catch almost all of our security holes before anything gets into the wild.  Also, I would not read anything into the vulnerability lists at Secunia, Bugtraq or CVE as they are only updated by security research firms who may not provide even coverage across all applications.  As a platform becomes more popular it obviously will get more scrutiny. 

From scanning the various security lists it is clear that vulnerabilities have been reported on both the core platforms as well as common modules, what is unclear is how many of the Joomla and Drupal modules actually ship with the product or are just made available from the project website.


Joe Brinkman
DNN Corp.
 
New Post
3/18/2008 9:43 AM
 

Thanks Joe and Sebastian for such great replies.

I am a cautious person so I feel very good about using DotNetNuke.  I know a "selling point" of Drupal and Joomla is the great variety of community modules but after seeing page after page of SQL injection problems and cross-site scripting I don't know if that is such a selling point.

I know that DNN community modules can have the same problems depending on the vendor.  But if you do a review of a module at DNN, do you check for some of the security vulnerabilities like SQL injection, etc.?

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...DNN Security on NIST CVEDNN Security on NIST CVE


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out