Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...security for dotnetnukesecurity for dotnetnuke
Previous
 
Next
New Post
7/6/2006 1:40 AM
 
IISLock is not needed with Win2003 becuase all of the feautures a built into Win2003.  I am pretty sure URLScan is not needed unless you just want to have an extra layer of protection.  Both of these utilities were written to make Win2000 more secure and are not needed on a Win2003 server if you know what you are doing.  And the comment about Win2003 being more secure out of the box is an accurate statement, but just like anything else if you choose to install/enable certain features on installation you can make it less secure but that is the choice of the installer.  When we install Win2003 we use the default install where very little is enabled so out of the box it is very secure.  The more you enable the less secure it will be.
 
New Post
7/6/2006 7:51 AM
 
DNN is not secure out of the box, since the host and admin login information appear right on the first page of each install. lol!

Jason Honingford - Web & Software Developer
www.PortVista.com
 
New Post
7/8/2006 3:06 PM
 
Jason,

Okay, you got me there, but is does state that you should change the password for these 2 accounts.  Although some users do not change default passwords like they should (eveident by the number of blank sa passwords for SQL Server that still exist).  Catch 22, since even if it was not on the first page of the installation, it is easy to find the default passwords for these accounts in the forums.

I got a good laugh from your response..........
 
New Post
7/8/2006 5:23 PM
 
Ya I made myself laugh on that one. ;) But a minor detail that could be improved down the road. It is possible you could create all new host and admin users and totally forget that you left the default host and admin accounts there. I suppose that's why on a lot of software installs, it either creates a random admin password, or asks you to supply one so the mistake cannot be made.

Jason Honingford - Web & Software Developer
www.PortVista.com
 
New Post
7/9/2006 12:57 AM
 
Good suggestion, can you please enter it as a feature request in our Issue/Feature DB at http://support.dotnetnuke.us.
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...security for dotnetnukesecurity for dotnetnuke


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out