Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Module ForumsModule ForumsBlogBlogMultiple portal Blog module security problemMultiple portal Blog module security problem
Previous
 
Next
New Post
6/8/2009 6:39 PM
 

I noticed that if I have multiple portals the blog entries can be retrieved for another portal just by changing the number. The entries that are written for another blog(another site) show up complete with my site layout as if I have written that. This in my opinion is a major security problem. SQL injection attacks are a real possibility if no validation is being done inside Blog module. Besides, if the individual portal  finds this, I may have to answer some very uncomfortable questions.

 
New Post
6/8/2009 9:57 PM
 

Hmmm, SQL Injection.... now that is a big word. Have you tried exploiting that "possibility"? Nevermind, that is a retoric question, because SQL injections are not possible ATM with this module.

As for the ability to change the ID... yes, you are correct, you can do that. Can you please add a ticket at http://support.dotnetnuke.com and reference this post?

Thank you.


Maxiom TechnologyAntonio Chagoury | Microsoft MVP
Maxiom Technology
Professional .net & DotNetNuke Solutions
web: www.maxiomtech.com
blog: www.cto20.com
twitter: @antoniochagoury & @maxiomtech

 
New Post
6/8/2009 11:46 PM
 

Antonio Chagoury wrote
 

Hmmm, SQL Injection.... now that is a big word. Have you tried exploiting that "possibility"? Nevermind, that is a retoric question, because SQL injections are not possible ATM with this module.

I am surprised that a person of your stature would just mock at a user reporting an injection  problem.

I am not an expert, not a programmer so let me apologize if I said something wrong. As per my salesworthy understanding, if by substituting a parameter I can receive data that I am not supposed to (in this case on a different portal), an SQL injection attack succeeded. The Blog module does not validate if the EntryID being asked for belongs to the currently shown portal and it is a problem if I , as a host am charging $$$ from clients who have individual portals and have posted Blog Entries of their own. Nobody wants to see their content being shown under another Portal's logo, skin and design.  Its a lawsuit waiting to happen for Dotnetnuke's paying customers.

<i> Also the reason I have not shown where this is happening </i>


As for the ability to change the ID... yes, you are correct, you can do that. Can you please add a ticket at http://support.dotnetnuke.com and reference this post?

I went to that page but how do I login there? My Dotnetnuke login does not work.

Thanks

Subodh

 
New Post
6/9/2009 8:21 AM
 

Subodh,

I was not mocking, I was simply trying to convey that changing a parameter in the URL and having the module STILL work is HARDLY SQL Injection.
SQL Injection is a SERIOUS vulnerability and NOT something I take lightly. SQL Injection could allow a hacker to EXPLOIT and/OR TRASH your entire database, AFTER stealing ALL YOU customer's information, of course.

If you can seriously compare the two issues and categorize them as the same level of vulnerability then, yes, accept my apologies for "mocking" you... otherwise, I would suggest you do just a little more research before posting such allegations without the proper back up.

To add a ticket, you need to create a new account on the support site - the DNN login DOES NOT work there.

Cheers,


Maxiom TechnologyAntonio Chagoury | Microsoft MVP
Maxiom Technology
Professional .net & DotNetNuke Solutions
web: www.maxiomtech.com
blog: www.cto20.com
twitter: @antoniochagoury & @maxiomtech

 
New Post
6/9/2009 5:08 PM
 

Excuse me, 

Stacy, is there a reason you dragged "subodh" - me;  in picture? I also saw just a few other posts you made and I must say it makes me unconfortable. If I need any PR, I can do it all by myself, thank you. I would appreciate if you would clarify why you seem to be impersonating me?

-Subodh aka www.subodh.com 

 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Module ForumsModule ForumsBlogBlogMultiple portal Blog module security problemMultiple portal Blog module security problem


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out