Small width layout Medium width layout Maximum width layout Small text Medium text Large text
     Search
Downloads Downloads Directory Directory Forums Forums Forge Forge Blogs Blogs        Marketplace Marketplace Careers Program Careers
Community › Forums Register  |  

DotNetNuke Marketplace
  Ads  
Engage Software - Training Partner for DotNetNuke
 


  Sponsors  

Meet Our Sponsors

telerik
ExactTarget email software solutions
Merak Mail Server
WebSecureStores -- ASP.NET & DotNetNuke Hosting Solutions
FCKeditor Project
Salaro -- Skins and more
 


DotNetNuke Forums
 
  Forum  General DotNetN...  Chat About It!  DNN Security on NIST CVE
Previous Previous
 
Next Next
New Post 3/17/2008 8:30 PM
Informative
User is offline irisheyes
7 posts
10th Ranked


DNN Security on NIST CVE 

I only run a few community sites on DNN but someone asked me about how secure some of the open source platforms were.  I knew that DNN was very good but I didn't have anything solid other than people just saying so.  The person asking me was interested in Drupal and Joomla in particular but CMS's in general.

So I went to the National Vulnerability Database at http://nvd.nist.gov/ to check things out.  Here's what I found when I went to the Vulnerabilities page and searched for Drupal, Joomla and DotNetNuke.

Drupal - 104 security concerns, 42 within the last year

Joomla - 213 security concerns, 125 within the last year

DotNetNuke - 7 security concerns, 0 within the last year

Looks really good, but before I "report back" to my friend, I've got a question. 

I'm not sure if the security vulnerabilities for Drupal and Joomla include all the community modules or if it is just the core.  Same with DotNetNuke.  I am not familiar with Drupal and Joomla to see if this is comparing apples to oranges.  I am hoping that someone who has looked at Drupal or Joomla would be able to recognize what components/modules/add-ons are part of the core offering (or maybe everything was core).

Anyone else want to take a look?

 
New Post 3/18/2008 4:07 AM
User is offline Sebastian Leupold
15216 posts
www.deutschnetnuke.de
1st Ranked












Re: DNN Security on NIST CVE 

AFAIK the number stated are covering core framework with default modules only, IMO there is no chance to cover all thousands of 3rd party modules. Said this, if you are concerning about security, you should be careful in selecting additional components, I use to by modules from serious and known vendors only. 


Sebastian Leupold

DeutschNetNuke dnnWerk - The DotNetNuke Experts German DotNetNuke User-Group

DotNetNuke Project UserDefinedTable
DotNetNuke Project Release Tracker
 
New Post 3/18/2008 5:53 AM
User is offline Joe Brinkman
1332 posts
www.dotnetnukecorp.com
6th Ranked






Re: DNN Security on NIST CVE 

PHP applications are notorious for their security issues, however that can be mitigated by doing a proper security review, both by the development team, and the team doing an implementation.  The DotNetNuke team is fortunate to have a security team headed by Cathal Connolly that reviews our code before we ship and we have recieved a couple of reports from various security audits over the years that has allowed us to further harden DotNetNuke and the core module.  This allows us to catch almost all of our security holes before anything gets into the wild.  Also, I would not read anything into the vulnerability lists at Secunia, Bugtraq or CVE as they are only updated by security research firms who may not provide even coverage across all applications.  As a platform becomes more popular it obviously will get more scrutiny. 

From scanning the various security lists it is clear that vulnerabilities have been reported on both the core platforms as well as common modules, what is unclear is how many of the Joomla and Drupal modules actually ship with the product or are just made available from the project website.


Joe Brinkman
DotNetNuke Corp.

The Accidental Geek - Joe Brinkman

 
New Post 3/18/2008 7:43 AM
User is offline irisheyes
7 posts
10th Ranked


Re: DNN Security on NIST CVE 

Thanks Joe and Sebastian for such great replies.

I am a cautious person so I feel very good about using DotNetNuke.  I know a "selling point" of Drupal and Joomla is the great variety of community modules but after seeing page after page of SQL injection problems and cross-site scripting I don't know if that is such a selling point.

I know that DNN community modules can have the same problems depending on the vendor.  But if you do a review of a module at DNN, do you check for some of the security vulnerabilities like SQL injection, etc.?

 
Previous Previous
 
Next Next
  Forum  General DotNetN...  Chat About It!  DNN Security on NIST CVE
 


Forum Policy

These Discussion Forums are dedicated to the discussion of the DotNetNuke Web Application Framework.

For the benefit of the community and to protect the integrity of the project, please observe the following posting guidelines:

1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DotNetNuke.
2. Discussion or promotion of DotNetNuke product releases under a different brand name are strictly prohibited.
3. No Flaming or Trolling.
4. No Profanity, Racism, or Prejudice.
5. Site Moderators have the final word on approving/removing a thread or post or comment.
6. English language posting only, please.

 


ADefWebserver.com
DotNetNuke® Module Development Help Website
ADefWebserver.com
Get Smarter Mail, SmarterStats, SmarterTickets
Windows mail server, web log analytics, and customer service management software - Free Editions Available!
www.smartertools.com
DotNetNuke Modules, Skins, Training and Consulting
If you want DotNetNuke done right then look no further. Developed Solutions provides module development, skin design, user and developer training and consulting. Based in Adelaide, Australia, we offer our services worldwide.
www.developedsolutions.com.au

DotNetNuke Corporation   Terms Of Use  Privacy Statement
DotNetNuke®, DNN®, and the DotNetNuke logo are trademarks of DotNetNuke Corporation
Hosted by MaximumASP