Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Security risk? - logging in as admin or host on public wifi Security risk? - logging in as admin or host on public wifi
Previous
 
Next
New Post
3/21/2010 4:40 PM
 

From what I can tell, most DNN sites do not use SSL.

From what I'm told, logging into sites that aren't https sends usernames and passwords as plain text in packets.

I'm also told that "hackers" can "sniff" these packets and get your login information.

Is this accurate?  If so, should we avoid logging in as host/admin/page editors on public wifi places like cafes and airports?

It sounds like we can buy an SSL ceritificate and make the login page SSL enforced.  Is this the best way to prevent "hacking" of DNN sites?

 

http://www.dotnetnuke.com/Community/Forums/tabid/795/forumid/108/threadid/354050/scope/posts/Default.aspx has info on SSL enforcing login page... but a quick "Step 1-10" would be helpful, if anyone knows more than me about it...

 
New Post
3/22/2010 9:32 AM
 

All that you've been told is true.  It's also true that you can get very pure water from core drilling the Antarctic ice and melting it in a lab.  Personally, I'm not paying for Antarctic core ice water when I can get very good bottled water at the corner grocery.

Nobody bothers to sniff passwords for your site in a coffeeshop.  Besides, you are changing your admin passwords regularly, correct?  As for SSL, it's not worth it except to secure financial data, which is what someone will be sniffing for.  As for the best way to prevent hacking, you're already vulnerable with that insecure password you never change, the fact that your password is the same as you use for other accounts and the fact that the guy at the next table can watch you type it.  Along with your weak FTP password, your unpatched server and the fact you don't use a VPN to access the server, your security is far easier to breech than sniffing your packets.

Jeff

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Security risk? - logging in as admin or host on public wifi Security risk? - logging in as admin or host on public wifi


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out