Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityCommunity Membe...Community Membe...Any PowerDNN users? Any PowerDNN users?
Previous
 
Next
New Post
5/21/2008 4:31 PM
 

Carlos Rodriguez wrote
...did not act in good faith...

Certainly PowerDNN realizes that the only difference between releasing the patch and the exploit itself is a few hours spent with the appropriate tools?

Brandon

 


Brandon Haynes
BrandonHaynes.org
 
New Post
5/21/2008 4:32 PM
 

Tony Valenti wrote

Hi All,
Just so everybody knows, I emailed Security@DotNetNuke.com two days ago when Joe R. and I first discovered the issue.  We did not receive any follow up or additional information.  I'll be resending the information shortly, but Shaun/Bill/Team - this is a critical issue!  Ya'll all have my phonenumber, but I don't have yours (and if you don't have mine, it is 402-650-6072).  Just Call me!  Let's work together and get this thing taken care of. ... 

 

@Tony - If I found a security issue in the core and didn't hear any response from an email to the security@dotnetnuke.com within 24 hours I would be following things up. If I thought the issue critical I would be finding other alternative means of contact.

@DNN Security Team - This thread has been going for quite a few hours and would have thought someone would have been able call PowerDNN.

Please lets get comunicating and ascertain the level of the risk and QA'ing the fixes PowerDNN have developed.

Antony

 
New Post
5/21/2008 4:33 PM
 

Data Springs Inc. wrote

So.... As of right now (1:15 PST), has the core team received the information on the bug / security issue?

Nothing yet on the security@dotnetnuke.com alias. As Joe mentioned, we monitor this alias diligently and treat messages sent to it as high priority.

Shaun has published a DotNetNuke Security Notice.

 


Nik Kalyani
Co-founder
DotNetNuke Corporation
Blog | Twitter | FaceBook
 
New Post
5/21/2008 4:38 PM
 

As a humble user of DotNetNuke, I'm a bit bewildered and concerened by all of this.

I still don't know if there is an issue.

I'm disappointed in what seems to be an issue with PowerDNN.

I'm also disappointed with the response of DotNetNuke.

 

Geez, you guys do know each other, and there MUST be phone numbers that you have ... or could find.  So, if this is such a critical issue, why aren't the phone lines buzzing?

Or is this just a tempest in a teapot?  If it is, I'd sure like to hear a definitive statement from DotNetNuke!

What's a poor boy to do in this sort of situation?

 




Joe Craig
Patapsco Research Group, Ellicott City, MD
DotNetNuke Development and Services (http://patapscorg.com)
 
New Post
5/21/2008 4:39 PM
 

I'd also prefer that my hoster not alter any of my site files especially without my permission. If they were the only ones that knew about it they should have first contacted DNN to provide a patch and then the patch could have been offered to users through normal channels. I'd rather make changes/patches to my site myself.

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityCommunity Membe...Community Membe...Any PowerDNN users? Any PowerDNN users?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out