Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Warning to any on WordPress...Warning to any on WordPress...
Previous
 
Next
New Post
6/29/2018 4:04 AM
 
Not to disparage WordPress, as it is a popular option for various reasons, but here's another reason I love DNN: Any known security holes get super-promptly filled!
One story currently running about WordPress and a 7 month old MAJOR issue:
A file deletion vulnerability that remains unpatched 7 months after being reported allows for the complete takeover of WordPress sites and for arbitrary code execution.
The security flaw supposedly impacts all WordPress versions, including the latest 4.9.6 iteration. An attacker looking to exploit the issue would first have to gain privileges to edit and delete media files.
“Thus, the vulnerability can be used to escalate privileges attained through the takeover of an account with a role as low as Author, or through the exploitation of another vulnerability/misconfiguration,” RIPS Technologies’ Karim El Ouerghemmi explains.
- Full story: https://www.securityweek.com/unpatched-wordpress-flaw-leads-site-takeover-code-execution
Also I read a story a few weeks back that indicated all recent releases of WordPress can be hacked to release email addresses of all user emails. WordPress apparently labels it a feature and refuses to change the behavior! (Sorry I cannot locate the story right now.)

Anyway, thanks to the security team at DNN. You've shown your professionalism with very rapid responses to any issues in the past decade!

 
New Post
6/29/2018 11:43 AM
 

Apparently there's some truth to this. I just received a scam email pretending to be a LinkedIn request when I looked at the URL the links were going to I laughed. I did go to the home page pf the site and found that all of it's styling and theming was gone. I also noticed that one of the links on the homepage was a good facebook link so I messaged the owner through FB to tell him his site has been hacked.

Here's the URL that the links were going to but I replaced the real domain:
http://SOMEWEBSITE.com/wp-content/themes/twentyfourteen/PO/Sign%20in%20to%20your%20Microsoft%20account.html

 

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Warning to any on WordPress...Warning to any on WordPress...


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out