Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...DNN 04.09.xx VS Fortify Source Code Analysis ToolDNN 04.09.xx VS Fortify Source Code Analysis Tool
Previous
 
Next
New Post
7/13/2009 2:15 PM
 

Cathal,

I understand.  I would want the same if I were in your position.  I wouldn't expect you to analyze 3rd party modules.

I will generate the output and get it to you asap.

I would like to be clear.  I'm not bashing the code.  I am greatful that so many of you have taken the time to build such an impressive product.  I'm very greatful for that.  I just wanted to contribute whatever I can to the project as well.  I do appreciate your time.

Thank you,

Tim

 
New Post
7/23/2009 4:15 PM
Accepted Answer 

Cathal,

I have since rescanned DNN 4.9.0 source code (without 3rd party modules) and the result is much more promising.  There were only 16 "hots" but my scan also produced a lot of errors.  I'll have to research those errors but I wanted to be responsible and tell the forum readers that there weren't nearly as many vulnerabilities as in my initial scan.  I am sorry for "crying wolf".  I have sent the report to the email address you specified.

Thanks again,

Tim

 
New Post
7/24/2009 2:05 PM
 

I work for a research company and use DNN for most of our projects. I am using 4.8.3 DNN version for one of my projects. Our client had run the Fortify tool to make sure there are no security issues and found 220 issues. Most of the issues were Cross-site scripting (42) issues found in the DNN modules.  These issues need to be fixed ASAP and I am not comfortable making changes to the DNN source code as I am also a newbie to DNN. Any help will be greatly appreciated. I am inluding the issues that fall under the severity range - Hot

[NOTE: This post was edited to remove security information - Joe Brinkman]

 
New Post
7/24/2009 8:26 PM
 

As a reminder to all users, it is against the DotNetNuke Security policy to post security vulnerability details in the open forums.  If you suspect there is a legitimate security issue with DotNetNuke then please submit your concerns to security@dotnetnuke.com and we will investigate the claim.  We take security very seriously on the project and do not want to provide hackers with ammunition with which they can attack community member's sites.


Joe Brinkman
DNN Corp.
 
New Post
8/4/2009 12:53 PM
 

My apologies.  I'm not sure what I was thinking.

I guess it wasn't clear to me how to submit the claim but I do now.  Thanks.

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...DNN 04.09.xx VS Fortify Source Code Analysis ToolDNN 04.09.xx VS Fortify Source Code Analysis Tool


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out