Small width layout Medium width layout Maximum width layout Small text Medium text Large text
     Search
Downloads Downloads Directory Directory Forums Forums Forge Forge Blogs Blogs        Marketplace Marketplace Careers Program Careers
Community › Forums Register  |  

telerik -- supercharge your DNN websites
  Ads  
Webhost4Life - $4.95 Windows Hosting
 


  Sponsors  

Meet Our Sponsors

Jango Studios - Skins, Modules and Hosting for DotNetNuke
eUKhost.com is commited to offer exceptional UK Windows Web Hosting solutions with quality 24x7 technical support.Our plans support ASP.Net, ASP, ASP.NET Ajax extensions, XML, MSSQL, MySQL, PHP,DNN, multiple domains and Shared SSL as standard.
SmarterTools
Verndale
The Official Microsoft ASP.NET Website
Portal Webhosting - Hosting For Developers
 


DotNetNuke Forums
 
  Forum  General DotNetN...  Chat About It!  PowerDNN: Put up or shut up
Previous Previous
 
Next Next
New Post 5/23/2008 8:42 AM
User is offline Ed DeGagne
313 posts
www.southvillagesoftware.com
8th Ranked


Re: PowerDNN: Put up or shut up 
Modified By Ed DeGagne  on 5/23/2008 11:23:15 AM)

The unprofessionalism of a public "lynching" by the original poster (and a few others) astounds me to no end.

I've been a customer of PowerDNN since their inception and have not had one single issue with the way they handle their end of the business. I am actually quite proud to have them "watching my back" instead of being an absentee landlord as a hoster.

They have been nothing but professional, courteous, helpful and completely knowledgable on the subject of hosting, DNN, and best practices. If they felt that there was a serious security flaw in DNN that could potentialy affect 1000's of installed client bases on THEIR SERVERS (which BTW is their property, not yours) then they had every right to alleviate that threat IMMEDIATELY until the core team could be notified and a proper fix released, if needed.

The only issue I take with PowerDNN themselves is that they released the information to the public through their site and through a press release prior to talking with the core team or Shawn personally. This lack of judgement, for lack of a better description, could have potentially affected many DNN users sites because of the very public nature of the information released.

I would only ask that EVERYONE out there follow the proper guidelines in reporting security issues to the core team and not publicly first. The interest of the entire DNN community is at risk when doing so.

It's quite unfortunate that a lack of judgement and professionalism was displayed in what is otherwise a very strong and courteous membership.

 

Edward DeGagne | Applications Engineering Manager
ektron, inc.
542 Amherst Street, Route 101A | Nashua, NH 03063


Ed DeGagne
South Village Software
 
New Post 5/23/2008 8:46 AM
User is offline Joe Yaya
23 posts
10th Ranked


Re: PowerDNN: Put up or shut up 

 Brandon Haynes wrote

It's truly unfortunate that you guys still don't get it.

Brandon

So what exactly don't they get? It looks to me like a case of  "no good deed goes unpunished."

Joe

 
New Post 5/23/2008 9:02 AM
User is offline B. Walker
100 posts
9th Ranked


Re: PowerDNN: Put up or shut up 

I hope this gives everybody out there a little more insight into what PowerDNN's primary concern was here:

http://www.emediawire.com/releases/DotNetNuke/Security/prweb964344.htm

So much for the "we just emailed our customers" line...

 
New Post 5/23/2008 10:23 AM
User is offline Joe Brinkman
1332 posts
www.dotnetnukecorp.com
6th Ranked






Re: PowerDNN: Put up or shut up 

Ed,

  People were more upset by the ongoing actions that occured long after PowerDNN had been told that they were detrimental to the community

1.  Ignoring the security reporting procedures which were put in place and which follow generally accepted practices for security professionals (guidelines).  Even if you accept that there first concern was protecting their customers, they had the time to create and post a security scanner which occured almost 12 hours before there was any communication with the core team.  This is not insignificant amount of time, and it is time that we could have been validating the bug and preparing a fix, along with presenting a unified response from both DotNetNuke and PowerDNN.

2.  Posting a security scanner which allowed any hacker to detect portal versions and quickly identify potential vulnerabilities.  Even after they were first requested to remove the scanner, it continued to remain online for more than 24 hours.

3.  Continuing to post false or misleading information regarding the events.

Given the nature of the particular vulnerabilties, there were remedies available to PowerDNN that did not require the alteration of any of their customers sites or the issuing of a security notification, much less creating a press release.  Also, because these vulnerabilities have existed for a couple of years there was no reason to create a panic in the community.  Prior to this there is no evidence that anyone had discovered much less exploited these vulnerabilities even though numerous audits by professional security organizations and governments had been performed.  Delaying notification until the DotNetNuke team had a chance to create a patch would not have jeapardized their own customers and would have kept the rest of the community safe until a permanent fix could have been distributed.


Joe Brinkman
DotNetNuke Corp.

The Accidental Geek - Joe Brinkman

 
New Post 5/23/2008 10:35 AM
User is offline Leazon
267 posts
9th Ranked


Re: PowerDNN: Put up or shut up 

You'll notice that the original poster of this thread has a grand total of 1 posts..........   Whomever this was needs to grow some nads and post under their usual account.
 A disappointed PowerDNN customer?  In three years I've never heard of one - I've heard complaints about the cost but never the service.

Greg

 
Previous Previous
 
Next Next
  Forum  General DotNetN...  Chat About It!  PowerDNN: Put up or shut up
 


Forum Policy

These Discussion Forums are dedicated to the discussion of the DotNetNuke Web Application Framework.

For the benefit of the community and to protect the integrity of the project, please observe the following posting guidelines:

1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DotNetNuke.
2. Discussion or promotion of DotNetNuke product releases under a different brand name are strictly prohibited.
3. No Flaming or Trolling.
4. No Profanity, Racism, or Prejudice.
5. Site Moderators have the final word on approving/removing a thread or post or comment.
6. English language posting only, please.

 


Overlook Technology
Website Development, DotNetNuke Consulting, Module Development, Portal Management
OverlookTechnology.com
DeutschNetNuke = DotNetNuke in German
DeutschNetNuke provides all DotNetNuke related services in German (and English).
www.DeutschNetNuke.de
The Standard in Senior Housing Information
SNAPforSeniors provides consumers with free online resources to assist them with their search for senior housing
www.snapforseniors.com

DotNetNuke Corporation   Terms Of Use  Privacy Statement
DotNetNuke®, DNN®, and the DotNetNuke logo are trademarks of DotNetNuke Corporation
Hosted by MaximumASP