﻿<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>Core :: Security</title>
    <description>Information and progress on matters of Core Security.</description>
    <link>http://www.dotnetnuke.com/Community/Blogs/tabid/825/BlogId/28/Default.aspx</link>
    <language>en-US</language>
    <webMaster>admin1@dotnetnuke.com</webMaster>
    <pubDate>Sun, 07 Sep 2008 07:22:24 GMT</pubDate>
    <lastBuildDate>Sun, 07 Sep 2008 07:22:24 GMT</lastBuildDate>
    <docs>http://backend.userland.com/rss</docs>
    <generator>Blog RSS Generator Version 3.4.0.39853</generator>
    <item>
      <title>Disabling support for persistent cookies</title>
      <description>&lt;p&gt;I've blogged &lt;a href="http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1784/Default.aspx"&gt;before&lt;/a&gt; about how to make timeouts work correctly for persistent cookies, but thought I should also flag up a minor, but often requested, enhancement that will be in DotNetNuke 5.0. Whilst persistent cookies are useful for a lot of sites in some cases they're not approriate. Sites that require a higher level of security such as many financial, insurance, government or ecommerce sites often do not want to offer the choice of persistent cookies to their users - we've had a number of security audit's sent in to the &lt;a href="http://www.dotnetnuke.commailto:security@dotnetnuke.com"&gt;security@dotnetnuke.com&lt;/a&gt; email alias where this has been flagged as an issue.&lt;/p&gt;
&lt;p&gt;In 5.0, we've added an option so that the "remember me" checkbox can be removed. To access this, log in as a superuser and go to the Host Settings menu. There you'll see the option to enable the remember me checkbox. By default this will be checked to match the existing behaviour, simply uncheck this to remove the "remember me" checkbox the the user.&lt;/p&gt;
&lt;p&gt;&lt;img height="30" alt="remember me checkbox" width="307" src="/Portals/25/PUBLIC/Incoming/ImagesForBlogs/remember_me.JPG" /&gt;&lt;/p&gt;
&lt;p&gt;If you want to set this option before installation, you can add &lt;RememberCheckbox&gt;N&lt;/RememberCheckbox&gt; as a node to the DotNetNuke.install.config&lt;/p&gt;</description>
      <link>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1885/Default.aspx</link>
      <comments>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1885/Default.aspx#Comments</comments>
      <guid isPermaLink="true">http://www.dotnetnuke.com/Default.aspx?tabid=825&amp;EntryID=1885</guid>
      <pubDate>Mon, 30 Jun 2008 23:58:00 GMT</pubDate>
      <slash:comments>7</slash:comments>
      <trackback:ping>http://www.dotnetnuke.com/DesktopModules/Blog/Trackback.aspx?id=1885</trackback:ping>
    </item>
    <item>
      <title>Removing the Administrator ability to upload skins</title>
      <description>&lt;p&gt;&amp;#160;&lt;/p&gt;</description>
      <link>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1877/Default.aspx</link>
      <comments>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1877/Default.aspx#Comments</comments>
      <guid isPermaLink="true">http://www.dotnetnuke.com/Default.aspx?tabid=825&amp;EntryID=1877</guid>
      <pubDate>Thu, 26 Jun 2008 01:18:00 GMT</pubDate>
      <slash:comments>30</slash:comments>
      <trackback:ping>http://www.dotnetnuke.com/DesktopModules/Blog/Trackback.aspx?id=1877</trackback:ping>
    </item>
    <item>
      <title>it never rains but it pours</title>
      <description>&lt;p&gt;As per the old &lt;a href="http://www.phrases.org.uk/bulletin_board/32/messages/265.html"&gt;proverb&lt;/a&gt;&amp;#160;, we're seeing a lot of activity around security these days.&lt;/p&gt;</description>
      <link>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1851/Default.aspx</link>
      <comments>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1851/Default.aspx#Comments</comments>
      <guid isPermaLink="true">http://www.dotnetnuke.com/Default.aspx?tabid=825&amp;EntryID=1851</guid>
      <pubDate>Sat, 31 May 2008 15:43:00 GMT</pubDate>
      <slash:comments>4</slash:comments>
      <trackback:ping>http://www.dotnetnuke.com/DesktopModules/Blog/Trackback.aspx?id=1851</trackback:ping>
    </item>
    <item>
      <title>Security bulletins released</title>
      <description>&lt;p&gt;&lt;span id="dnn_ctr2612_MainView_ViewEntry_lblEntry"&gt;The 4.8.2 version of DotNetNuke has been released.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;br /&gt;
In many cases the best way to ensure you're running a secure version of DotNetNuke is to update to a version such as 4.8.2 that has no known vulnerabilities. Oddly enough, in this case the upgrade is not mandatory. The release mainly focuses on 3 security issues, 2 of which came from external sources, and one from a project team member (thanks Timo!). The &lt;a href="http://www.dotnetnuke.com/News/SecurityBulletins/SecurityBulletinno11/tabid/1147/Default.aspx"&gt;first&lt;/a&gt; and &lt;a href="http://www.dotnetnuke.com/News/SecurityBulletins/SecurityBulletinno13/tabid/1149/Default.aspx"&gt;third&lt;/a&gt; issues could allow a user with upload permissions a way to upload files/pages that contain code, and then use this code to escalate their permissions or gain access to code/resources. In both cases these need a minimum of Admin permissions. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;The &lt;a href="http://www.dotnetnuke.com/News/SecurityBulletins/SecurityBulletinno12/tabid/1148/Default.aspx"&gt;second&lt;/a&gt; issue is to deal with a rare case where the validationkey in your web.config does not get updated from the default value. If on your site you don't have Admin users or the known key (validationkey="F9D1A2D3E1D3E2F7B3D9F90FF3965ABDAC304902") in your web.config, then you can choose to wait to apply this upgrade. Please note, 4.8.2 also has code to fix an ajax &lt;a href="http://support.dotnetnuke.com/issue/ViewIssue.aspx?id=6862&amp;PROJID=2"&gt;issue&lt;/a&gt;, so if you use components that utilise MS Ajax, it's definately worth thinking about an upgrade.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;If you're new to upgrading I recommend you read the "detailed installation guide" found &lt;a href="http://www.dotnetnuke.com/Resources/Documentation/DownloadableFiles/tabid/478/Default.aspx"&gt;here&lt;/a&gt; , and the excellent set of blog entries from Erik &lt;a href="http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1459/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1459/Default.aspx"&gt;here&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;You can read more details about these issues and our security policy &lt;a href="http://www.dotnetnuke.com/About/WhatIsDotNetNuke/SecurityPolicy/tabid/940/Default.aspx"&gt;&lt;font color="#75808a"&gt;here&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <link>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1768/Default.aspx</link>
      <comments>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1768/Default.aspx#Comments</comments>
      <guid isPermaLink="true">http://www.dotnetnuke.com/Default.aspx?tabid=825&amp;EntryID=1768</guid>
      <pubDate>Thu, 20 Mar 2008 23:44:00 GMT</pubDate>
      <slash:comments>1</slash:comments>
      <trackback:ping>http://www.dotnetnuke.com/DesktopModules/Blog/Trackback.aspx?id=1768</trackback:ping>
    </item>
    <item>
      <title>Security Bulletin released</title>
      <description>&lt;p&gt;The newly released 4.7 version of DotNetNuke contain fixes for a number of security issues discovered during internal testing. The relevant bulletins can be found &lt;a href="http://www.dotnetnuke.com/News/SecurityBulletins/Policy/Securitybulletinno9/tabid/1135/Default.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://www.dotnetnuke.com/News/SecurityBulletins/Policy/Securitybulletinno10/tabid/1136/Default.aspx"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;You can read more details about these issues and our security policy &lt;a href="http://www.dotnetnuke.com/About/WhatIsDotNetNuke/SecurityPolicy/tabid/940/Default.aspx"&gt;&lt;font color="#75808a"&gt;here&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <link>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1666/Default.aspx</link>
      <comments>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1666/Default.aspx#Comments</comments>
      <guid isPermaLink="true">http://www.dotnetnuke.com/Default.aspx?tabid=825&amp;EntryID=1666</guid>
      <pubDate>Tue, 04 Dec 2007 00:38:54 GMT</pubDate>
      <slash:comments>2</slash:comments>
      <trackback:ping>http://www.dotnetnuke.com/DesktopModules/Blog/Trackback.aspx?id=1666</trackback:ping>
    </item>
    <item>
      <title>Security Bulletin released - Potential Phishing issue </title>
      <description>&lt;p&gt;&lt;span class="Normal" id="dnn_ctr2612_MainView_ViewEntry_lblEntry"&gt;&lt;span class="Normal" id="dnn_ctr2612_MainView_ViewEntry_lblEntry"&gt;&lt;span class="Normal" id="dnn_ctr2612_MainView_ViewEntry_lblEntry"&gt;&lt;span class="Normal" id="dnn_ctr2612_MainView_ViewEntry_lblEntry"&gt;This issue involves a potential &lt;a href="http://en.wikipedia.org/wiki/Phishing"&gt;&lt;font color="#75808a"&gt;phishing&lt;/font&gt;&lt;/a&gt; risk in the login code, where malicious users could create a link to a legitimate login page with an untrusted location as the return path to fool users into thinking another site was the site they just logged into. Whilst this issue cannot cause harm on the users portal itself, as it can lead to a loss of confidence in a site, we elected to give this issue a status of &lt;a href="http://www.dotnetnuke.com/Community/SecurityPolicy/tabid/940/Default.aspx"&gt;&lt;font color="#75808a"&gt;medium&lt;/font&gt;&lt;/a&gt;. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;
&lt;p&gt;&lt;span class="Normal" id="dnn_ctr2612_MainView_ViewEntry_lblEntry"&gt;&lt;span class="Normal" id="dnn_ctr2612_MainView_ViewEntry_lblEntry"&gt;&lt;span class="Normal" id="dnn_ctr2612_MainView_ViewEntry_lblEntry"&gt;We recommend users update their portal version to the latest 4.5.4 release to remove this issue. Please read the &lt;a href="http://www.dotnetnuke.com/News/SecurityBulletins/Securitybulletinno8/tabid/1110/Default.aspx"&gt;&lt;font color="#75808a"&gt;bulletin&lt;/font&gt;&lt;/a&gt; for further details. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;You can read more details about these issues and our security policy &lt;a href="http://www.dotnetnuke.com/About/WhatIsDotNetNuke/SecurityPolicy/tabid/940/Default.aspx"&gt;here&lt;/a&gt;&lt;/p&gt;
&lt;/span&gt;&lt;/p&gt;</description>
      <link>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1498/Default.aspx</link>
      <comments>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1498/Default.aspx#Comments</comments>
      <guid isPermaLink="true">http://www.dotnetnuke.com/Default.aspx?tabid=825&amp;EntryID=1498</guid>
      <pubDate>Mon, 23 Jul 2007 21:36:15 GMT</pubDate>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.dotnetnuke.com/DesktopModules/Blog/Trackback.aspx?id=1498</trackback:ping>
    </item>
    <item>
      <title>Forums module updated to address security issues</title>
      <description>A new version of the forum module has been released to deal with some critical issues</description>
      <link>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1395/Default.aspx</link>
      <comments>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1395/Default.aspx#Comments</comments>
      <guid isPermaLink="true">http://www.dotnetnuke.com/Default.aspx?tabid=825&amp;EntryID=1395</guid>
      <pubDate>Wed, 11 Apr 2007 04:23:00 GMT</pubDate>
      <slash:comments>8</slash:comments>
      <trackback:ping>http://www.dotnetnuke.com/DesktopModules/Blog/Trackback.aspx?id=1395</trackback:ping>
    </item>
    <item>
      <title>Security Bulletin released - Potential Phishing issue</title>
      <description>&lt;p&gt;&lt;span class="Normal" id="dnn_ctr2612_MainView_ViewEntry_lblEntry"&gt;&lt;span class="Normal" id="dnn_ctr2612_MainView_ViewEntry_lblEntry"&gt;&lt;span class="Normal" id="dnn_ctr2612_MainView_ViewEntry_lblEntry"&gt;This issue involves a potential &lt;a href="http://en.wikipedia.org/wiki/Phishing"&gt;phishing&lt;/a&gt; risk where malicious users could create a link that appeared to be approved by a site owner, that might convince an unwary user to visit an untrustworthy location. Whilst this issue cannot cause harm on the users portal itself, as it can lead to a loss of confidence in a site, we elected to give this issue a status of &lt;a href="http://www.dotnetnuke.com/Community/SecurityPolicy/tabid/940/Default.aspx"&gt;medium&lt;/a&gt;. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span class="Normal" id="dnn_ctr2612_MainView_ViewEntry_lblEntry"&gt;&lt;span class="Normal" id="dnn_ctr2612_MainView_ViewEntry_lblEntry"&gt;&lt;span class="Normal" id="dnn_ctr2612_MainView_ViewEntry_lblEntry"&gt;We recommend users update their portal version to the latest 4.5 release to remove this issue. Please read the &lt;a href="http://www.dotnetnuke.com/Community/SecurityPolicy/SecurityBulletinno7/tabid/1045/Default.aspx"&gt;bulletin&lt;/a&gt; for further details. &lt;/span&gt;&lt;/span&gt;&lt;span class="Normal"&gt;&lt;span class="Normal"&gt;
&lt;p&gt;You can read more details about these issues and our security policy &lt;a href="http://www.dotnetnuke.com/About/WhatIsDotNetNuke/SecurityPolicy/tabid/940/Default.aspx" target="_blank"&gt;&lt;font color="#75808a"&gt;here&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;</description>
      <link>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1394/Default.aspx</link>
      <comments>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1394/Default.aspx#Comments</comments>
      <guid isPermaLink="true">http://www.dotnetnuke.com/Default.aspx?tabid=825&amp;EntryID=1394</guid>
      <pubDate>Tue, 10 Apr 2007 23:48:00 GMT</pubDate>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.dotnetnuke.com/DesktopModules/Blog/Trackback.aspx?id=1394</trackback:ping>
    </item>
    <item>
      <title>Security Bulletin released </title>
      <description>&lt;p&gt;&lt;span class="Normal" id="dnn_ctr2612_MainView_ViewEntry_lblEntry"&gt;&lt;span class="Normal" id="dnn_ctr2612_MainView_ViewEntry_lblEntry"&gt;The newly released 3.3.7/4.3.7 versions contain a fix for a &lt;a target="_blank" href="http://www.dotnetnuke.com/tabid/940/Default.aspx"&gt;medium&lt;/a&gt; security issue where anonymous users could gain access to vendor details, and create, delete and update them. There are some mitigating factors i.e. for this issue to have an effect you would have to have enabled vendors and be using the banners module, but we advise all users to update to the latest versions. The issue can also be resolved by running a sql script to update the approriate database record, please read the &lt;a target="_blank" href="http://www.dotnetnuke.com/About/WhatIsDotNetNuke/SecurityPolicy/SecurityBulletinno6/tabid/1019/Default.aspx"&gt;bulletin&lt;/a&gt; for further details.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;span class="Normal"&gt;&lt;span class="Normal"&gt;
&lt;p&gt;You can read more details about these issues and our security policy &lt;a target="_blank" href="http://www.dotnetnuke.com/About/WhatIsDotNetNuke/SecurityPolicy/tabid/940/Default.aspx"&gt;here&lt;/a&gt;&lt;/p&gt;
&lt;/span&gt;&lt;/span&gt;</description>
      <link>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1206/Default.aspx</link>
      <comments>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1206/Default.aspx#Comments</comments>
      <guid isPermaLink="true">http://www.dotnetnuke.com/Default.aspx?tabid=825&amp;EntryID=1206</guid>
      <pubDate>Sat, 02 Dec 2006 00:00:00 GMT</pubDate>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.dotnetnuke.com/DesktopModules/Blog/Trackback.aspx?id=1206</trackback:ping>
    </item>
    <item>
      <title>Security Bulletin released </title>
      <description>&lt;P&gt;&lt;SPAN class=Normal id=dnn_ctr2612_MainView_ViewEntry_lblEntry&gt;The newly released 3.3.6/4.3.6 versions, contain a number of security fixes. These were brought to our attention by David Kirby &amp; Christiaan Mellars of Risborrow Information Systems Ltd. One of the bulletins discusses an issue rated as &lt;A href="http://www.dotnetnuke.com/About/WhatIsDotNetNuke/SecurityPolicy/SecurityBulletinno4/tabid/1017/Default.aspx" target=_blank&gt;critical&lt;/A&gt; and the other discusses two problems fixed as part of a &lt;A href="http://www.dotnetnuke.com/About/WhatIsDotNetNuke/SecurityPolicy/SecurityBulletinno5/tabid/1018/Default.aspx"&gt;low&lt;/A&gt; impact issue.  &lt;/SPAN&gt;&lt;SPAN class=Normal&gt;To fix these issues you are recommended to update to either 3.3.6 or 4.3.6.&lt;/P&gt;
&lt;P&gt;You can read more details about these issues and our security policy &lt;A href="http://www.dotnetnuke.com/About/WhatIsDotNetNuke/SecurityPolicy/tabid/940/Default.aspx" target=_blank&gt;here&lt;/A&gt;&lt;/P&gt;&lt;/SPAN&gt;</description>
      <link>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1189/Default.aspx</link>
      <comments>http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/1189/Default.aspx#Comments</comments>
      <guid isPermaLink="true">http://www.dotnetnuke.com/Default.aspx?tabid=825&amp;EntryID=1189</guid>
      <pubDate>Fri, 17 Nov 2006 05:00:00 GMT</pubDate>
      <slash:comments>0</slash:comments>
      <trackback:ping>http://www.dotnetnuke.com/DesktopModules/Blog/Trackback.aspx?id=1189</trackback:ping>
    </item>
  </channel>
</rss>