Small width layout Medium width layout Maximum width layout Small text Medium text Large text
     Search
Downloads Downloads Directory Directory Forums Forums Forge Forge Blogs Blogs        Marketplace Marketplace Careers Program Careers
Community › Forums Register  |  

DotNetNuke Marketplace
  Need Help?  
Professional technical support for DotNetNuke is available from DotNetNuke Corporation.
 


  Ads  
Active Modules -- Active Forums for DotNetNuke
 


  Sponsors  

Meet Our Sponsors

SmarterTools
The Official Microsoft ASP.NET Website
Portal Webhosting - Hosting For Developers
Red-Gate Software
MaximumASP
SourceGear - Tools for Developers
 


DotNetNuke Forums
 
  Forum  General DotNetN...  Announce It! ( ...  Any PowerDNN users?
Previous Previous
 
Next Next
New Post 5/21/2008 12:20 PM
User is offline Joe Brinkman
1304 posts
www.dotnetnukecorp.com
6th Ranked






Re: Any PowerDNN users?  

Mitchel,

  Michael specifically has not been contacted and is just as upset as the rest of us over the way this has been handled.


Joe Brinkman
DotNetNuke Corp.

The Accidental Geek - Joe Brinkman

 
New Post 5/21/2008 12:26 PM
User is offline Mitch Sellers
5566 posts
www.mitchelsellers.com
3rd Ranked




Re: Any PowerDNN users?  

 Joe Brinkman wrote

Mitchel,

  Michael specifically has not been contacted and is just as upset as the rest of us over the way this has been handled.

I had a feeling that was the case......

...this is sure turning into an interesting saga....

Special thanks to Shaun, Joe, and the rest of the core team that is digging into this item, I'm sure that this is not something you guys were looking to deal with on a Wednesday...


-Mitchel Sellers
MCITP, MCPD, MCTS
CEO/Director of Development - IowaComputerGurus Inc.
LinkedIn Profile

Visit mitchelsellers.com for my mostly DNN Blog and support forum.

Visit IowaComputerGurus.com for free DNN Modules, DNN Consulting Quotes, and DNN Technical Support Services

I reccomend 3Essentials for shared hosting and BaseCamp for project management
 
New Post 5/21/2008 12:30 PM
User is offline JohnGrange
53 posts
10th Ranked


Re: Any PowerDNN users?  

Just to clarify, we did not submit a report to security@dotnetnuke.com as of yet, but we were in contact with members of the core team this morning.  As I write this we are putting together a report for security@dotnetnuke.com.  Also, no PowerDNN customer was charged anything for this patch, as it is our responsibility to ensure the security of their installations.  Again, from a resource perspective we have to charge non-customers for time spent on a patch.  We were forced to send out a blast e-mail to all of our customers about the vulnerability because many of them have development installations that would overwrite the patch if they weren't


PowerDNN DNN hosting
 
New Post 5/21/2008 12:31 PM
Online now... Michael Washington
2757 posts
ADefWebserver.com
5th Ranked










Re: Any PowerDNN users?  

 Mitch Sellers wrote

Joe,

I'm not sure if it helps or not, but I've heard through a few grapevines today that Michael Washington might have been contacted....

I had assumed that PowerDNN gave the information to security@dotnetnuke.com and the Core hadn't responded yet. When there is an exploit normal Core members get the details when the rest of the community gets the details because only the people working on the problem "need to know".

I was contacted by a PowerDNN representative when I asked for the patch fix for free. I was told to give FTP access to my site. I then found out the the Core was not told about the patch.

Then my "Head exploded". I then sent a email to PowerDNN telling them that I thought it was wrong to sell the patch.

So my mistake was asking for the patch for free. I should not have done that. I should have sent PowerDNN an email telling them that it is wrong to sell a security patch for Open Source software under any circumstances. The source is "open" so that we can all "protect each other".

PowerDNN cannot call it a "service" to "patch it for us" because they don't want to "tell us what the exploit is".

How about this, when the next bug comes out, how about I charge for it?



Michael Washington
* ADefWebserver.com
* DNN Module Developer's Guide
* IWEB - DNN Web Services
* Silverlight and DotNetNuke
 
New Post 5/21/2008 12:35 PM
User is offline B. Walker
75 posts
10th Ranked


Re: Any PowerDNN users?  

Aside from the security@dotnetnuke.com address, which every long-standing developer in the community knows about, there are several points of contact listed on the DotNetNuke.com "Contacts" page.  These are for webmaster@, advertising@, and sales@.  I am a recipient on each of these lists, and have NOT received any communication from PowerDNN on this matter (whereas in the past, I have been reached several times via these channels by parties reporting potential security issues.) Now, keep in mind that the email circulated by PowerDNN stated they first learned about the problem on Monday evening, broadcast it on Tuesday PM, and didn't email any of our contact points.  Curious...

 
Previous Previous
 
Next Next
  Forum  General DotNetN...  Announce It! ( ...  Any PowerDNN users?
 


Forum Policy

These Discussion Forums are dedicated to the discussion of the DotNetNuke Web Application Framework.

For the benefit of the community and to protect the integrity of the project, please observe the following posting guidelines:

1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DotNetNuke.
2. Discussion or promotion of DotNetNuke product releases under a different brand name are strictly prohibited.
3. No Flaming or Trolling.
4. No Profanity, Racism, or Prejudice.
5. Site Moderators have the final word on approving/removing a thread or post or comment.
6. English language posting only, please.

 


Swanzey Internet Group LLC
DotNetNuke design, development, e-Commerce, hosting, maintenance, and training. Exclusively DotNetNuke.
www.swanzey.com
Lucede Systems Group
Providing a full range of IT services for large and medium sized companies
www.lucede.com
Adaptive InfoSystems, Inc.
We provide custom programming and various levels of support for DotNetNuke and the .Net framework.
www.aisysweb.com

DotNetNuke Corporation   Terms Of Use  Privacy Statement
DotNetNuke®, DNN®, and the DotNetNuke logo are trademarks of DotNetNuke Corporation
Hosted by MaximumASP