| |
|
|
|
|
|
|
|
|
|
 |    |  |
 | |  |
 | |  |
 | |  |
 | |  |
 |
|
|
|
| JohnGrange wrote
Hi Guys,
When we discovered this vulnerability, it was found to be such a critical issue that we were compelled to secure our customers right away. Our first responsibility is always going to be to make sure that PowerDNN customers are running high performance, secure, DNN installations. Our customers have been overwhelmingly thankful for the hard work we've done to secure their sites. Our team is putting together an official report which we will release to the community, it is important that everyone is aware of the issue. We have been in contact with certain members of the core team as well as many of the top vendors in the community. In terms of the $20, we could take that away but then we wouldn't be able to patch non-PowerDNN customers in any way that would be financially feasible. If we got rid of the $20 charge, we could scan your site but not perform any fix. This issue effects so many sites that we want to protect community by releasing the information in a thoughtful way. We will get the information out via the normal DNN channels, but, we view this issue as being critical enough that waiting until the next release of DNN is not sufficient and we were compelled to take action immediately. I hope this clears some things up for some people, we take issues like this very seriously, because like most of you, we love DotNetNuke and it is our livelyhood.
John Grange
|
I hope fof PowerDNN's sake that the core team was contacted immediately. As it looks now, a pretty key member of the core team had no idea about this. You have a tool, for $20, that can patch this, which implies that the core team could also patch this vulnerability pretty quickly. Chris |
|
|
|
 |  |
|
|
|
I am one of the members of our Security Task Force and actively monitor security@dotnetnuke.com. I can assure you that we have received NO COMMUNICATION from PowerDNN in regards to this issue. Instead, we have received a ton of email from PowerDNN hosting customers who are wondering why PowerDNN is charging for this information. I have no good answer for that question... Shaun Walker
President / Chief Architect
DotNetNuke Corporation |
|
|
|
 |  |
|
|
|
| GMartin wrote
| Tony Valenti wrote
Hey Dan,
We are working with the DotNetNuke Core Team to make this patch available to everyone. We're not releasing the patch to the public as of yet because if the wrong people became aware of the flaw or its location, it would mean catastrophe for almost any non-PowerDNN customer who has set up DotNetNuke within the past year.
During this "Zero Day" time period, we are offering a service where our engineers will work with companies for virtually free to help them patch their mission critical websites while the DotNetNuke core team creates an "official" resolution to the issues.
I understand that you're really curious about what the flaw was, however, if you notice any changes, please hold back from discussing them.
Always glad to help,
-Tony Valenti
|
But what if malfeasants are able to come up with $20? Are the PowerDNN engineers asking any trick questions to ensure that people buying the fix have good intensions?
|
From what I understand of the actual fix, this should hopefully be a minimal issue as the change is inside one of the compiled .dll files for DotNetNuke. -Mitchel Sellers
MCITP, MCPD, MCTS
CEO/Director of Development - IowaComputerGurus Inc.

Visit mitchelsellers.com for my mostly DNN Blog and support forum.
Visit IowaComputerGurus.com for free DNN Modules, DNN Consulting Quotes, and DNN Technical Support Services
I reccomend 3Essentials for shared hosting and BaseCamp for project management |
|
|
|
 |  |
|
|
|
| Chris McCandless wrote
I hope fof PowerDNN's sake that the core team was contacted immediately. As it looks now, a pretty key member of the core team had no idea about this. You have a tool, for $20, that can patch this, which implies that the core team could also patch this vulnerability pretty quickly.
|
Chris, I am not aware of anyone on the core team who has been contacted, and there have certainly been quite a few posts about this in the private team forums. Specifically, no one from the DotNetNuke management or security teams have been contacted. In the meantime we will continue to do our own security analysis to see if there is something we have missed, although that would certainly be easier if someone from PowerDNN would send a short email to security@dotnetnuke.com outlining the specific vulnerabilities involved. Even without a detailed analysis and fix it would help us isolate our search and come up with a patch that could be made available to the community. Joe Brinkman
DotNetNuke Corp.

|
|
|
|
 |  |
|
|
|
| Joe Brinkman wrote
| Chris McCandless wrote
I hope fof PowerDNN's sake that the core team was contacted immediately. As it looks now, a pretty key member of the core team had no idea about this. You have a tool, for $20, that can patch this, which implies that the core team could also patch this vulnerability pretty quickly.
|
Chris, I am not aware of anyone on the core team who has been contacted, and there have certainly been quite a few posts about this in the private team forums. Specifically, no one from the DotNetNuke management or security teams have been contacted. In the meantime we will continue to do our own security analysis to see if there is something we have missed, although that would certainly be easier if someone from PowerDNN would send a short email to security@dotnetnuke.com outlining the specific vulnerabilities involved. Even without a detailed analysis and fix it would help us isolate our search and come up with a patch that could be made available to the community.
|
Joe,
I'm not sure if it helps or not, but I've heard through a few grapevines today that Michael Washington might have been contacted....
EDIT: Per future post from Joe, I had been incorrectly informed. I just wanted to be sure to note this here as this is the last post on the page. -Mitchel Sellers
MCITP, MCPD, MCTS
CEO/Director of Development - IowaComputerGurus Inc.

Visit mitchelsellers.com for my mostly DNN Blog and support forum.
Visit IowaComputerGurus.com for free DNN Modules, DNN Consulting Quotes, and DNN Technical Support Services
I reccomend 3Essentials for shared hosting and BaseCamp for project management |
|
|
|
|  |
 | |  |
 | |  |
 | |  |
|  |
| |
 |
|
These Discussion Forums are dedicated to the discussion of the DotNetNuke Web Application Framework.
For the benefit of the community and to protect the integrity of the project, please observe the following posting guidelines:
1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DotNetNuke.
2. Discussion or promotion of DotNetNuke product releases under a different brand name are strictly prohibited.
3. No Flaming or Trolling.
4. No Profanity, Racism, or Prejudice.
5. Site Moderators have the final word on approving/removing a thread or post or comment.
6. English language posting only, please.
|
| |
 |
|
|
|
|
Customer Connect Customer Connect provides cutting edge solutions that deliver sales, marketing and customer service results. www.customer-connect.com
|
TechNexxus Business process and technology sourcing solutions delivering superior people, process and value. We have used, and continue to use, DNN successfully in numerous client projects to deliver exceptional value. We are proud to support the DNN team and community. www.technexxus.com
|
PartnerPoint - Microsoft Technology Community PartnerPoint is one of the largest online communities of Microsoft Partners Worldwide. With over 5,000 active members, it serves as a collaboration platform for other technology communties around the globe www.partnerpoint.com
|
|
|
|