Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityCommunity Membe...Community Membe...Any PowerDNN users? Any PowerDNN users?
Previous
 
Next
New Post
5/21/2008 5:18 PM
 

FYI I received the following e-mail from PowerDNN (I am not responsible for content, simply pasting directly from my e-mail)

Hi Mitch,

Sorry about the delay, as you can imagine we have been busy today.  I actually addressed your concern in the forums but DNN is currently censoring my and Tony's posts which is unfortunate as some things have been said which are inaccurate.  Just to clarify, our scanner only checks for a versions then cross references it with a bug database.  It doesn't pass any sensitive information other than version number.  The tool merely tells your if you're vulnerable based on the version of DNN you are running.  We are going to put a notice on the tool clarifying this as well as adding some verification feature as well. Please let people know that we really want to address some of these things in the forums but we are not able to.  Thanks, give me a call if you have anymore questions or need anything.
--
John Grange
PowerDNN
Vice President

I sent the following reply (Again, just to keep everyone updated on this issue)

 

 

 

Hi John,
 
I'm sorry to hear that your messages have not gone through.  I will simply post this reply in the forums for all to read.
 
In regards to the issue, still allowing ANY site to be put in and providing version information is a security risk in of itself.  If there is a person with ill intentions out there that kows what the details are of a vulnerability, this tool will provide them information to know if the site is or is not affected.  Granted it is most likely not a major issue, but it was enough of an issue for the core team to remove the version from the "Show Copyright Credits" option.
 

-Mitchel Sellers
Microsoft MVP, ASPInsider, DNN MVP
CEO/Director of Development - IowaComputerGurus Inc.
LinkedIn Profile

Visit mitchelsellers.com for my mostly DNN Blog and support forum.

Visit IowaComputerGurus.com for free DNN Modules, DNN Performance Tips, DNN Consulting Quotes, and DNN Technical Support Services
 
New Post
5/21/2008 5:23 PM
 

I think people are also misunderstanding the situation in a number of ways.  One, we absolutely had to e-mail our customers about this issue for the reasons I have already stated.  Two, we have a number of different service levels that require different levels of attention.  We developed a scan and patch tool immediately because our Atomic SLA customers get features like this as part of their subscription.  So we basically reported the issue to the Core the day after we patched our our customers.  The real problem here is that because we had so many clients effected it was bound to get to the forums and cause some hysteria.  Honestly, this was not anticipated but probably should have been.  In the future we will approach things a little differently based on what's been said in this thread.  The real issue is that non-customers feel like we have done the community a disservice by not contacting the core team first.  When we realized the severity of the issue we secured our stuff first and within 24 hours reported to the core.  I do not believe this is very far off form what other companies would do except our issue just happened to become very public. 

We have recieved overwhelmingly positive feedback from both hosting and Atomic SLA customers on this issue.  I hope everyone can understand the position we are in, and look at the facts and see that we didn't withhold all this information for days in a plan to hurt the community.  We tout ourselves as being the best, which means we have to constantly be going abve and beyond for our customers.  Our business customers demand high end heavily support services, these are all things we have to take into account when faced with issues like this.

 
New Post
5/21/2008 5:25 PM
 

WEBPC wrote
@DNN Security Team - This thread has been going for quite a few hours and would have thought someone would have been able call PowerDNN.
Please lets get comunicating and ascertain the level of the risk and QA'ing the fixes PowerDNN have developed.
Antony

You can bet the security team is using every method at their disposal, and probably having to cancel their previous engagements in order to resolve this.

Not only are there apparent vulnerabilities with sketchy details, but we now have a site that allows Tom, Dick, Harry, everybody else, and their dog to look at the security issues of everyone’s DNN website in mere seconds. IF indeed the website actually scans and checks for vulnerabilities rather than just anticipate them?... and all of us dance around like headless chickens :). In this case I think we are entitled to, that is because we don't exactly know the impact, because rightly or wrongly we assume the worst, and because the cat was out of the bag before the solution was made available. Plus there is a tool that apparently allows me to know that YOUR website is effected.



Alex Shirley


 
New Post
5/21/2008 5:29 PM
 

John,

  Do you have a timeframe on the missing forum posts?  I am not aware of any deleted postings (which are sent to moderators) but it is possible that a moderator is being overly cautious to make sure that exploit data is kept out of the public forums.


Joe Brinkman
DNN Corp.
 
New Post
5/21/2008 5:33 PM
 

Hi Joe,

I am thinking something got messed up somewhere because I never got a notification about the post.  I might not have been getting modded but back at about page 9 I had posted twice and it never went up.  I didn't want to post anything public since I am not positive I was being blocked, I also know that your mod team is always working very hard to get posts out and they could have got backed up.  It looked like my last post went out so I could have been wrong.  I wasn' t expecting my e-mail to Mitch to be public but no harm done.  I hope some of the confusion has passed us, I think we have all had kind of a wild day.

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityCommunity Membe...Community Membe...Any PowerDNN users? Any PowerDNN users?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out