Small width layout Medium width layout Maximum width layout Small text Medium text Large text
     Search
Downloads Downloads Directory Directory Forums Forums Forge Forge Blogs Blogs        Marketplace Marketplace Careers Program Careers
Community › Forums Register  |  

$4.95 Windows Hosting at Webhost4life.com
  Ads  
Active Modules -- Active Forums for DotNetNuke
 


  Sponsors  

Meet Our Sponsors

FCKeditor Project
Salaro -- Skins and more
OnyakTech
CrystalTech Web Hosting™
Webhost4life, specialists in DNN hosting
Mad Development is a full service interactive agency focusing on the merge of design, technology, e-commerce, and affiliate marketing by providing total website solutions.
 


DotNetNuke Forums
 
  Forum  General DotNetN...  Chat About It!  PowerDNN Security Hotfix
Previous Previous
 
Next Next
New Post 5/23/2008 10:33 AM
User is offline Charles Nurse
2915 posts
5th Ranked










Re: PowerDNN Security Hotfix 

 Bill Yonder wrote

1)  Why is the core team spending all their time flaming PowerDNN and not releasing a patch?

Mainly because it took PowerDNN two days to inform us as to what the issue was - you can't fix issues in a vacuum.

 Bill Yonder wrote

2)  Why is it that DotNetNuke.com is patched but the core team has not released the fixes to the public?

Why is it that you think this site is patched?  What evidence do you have.  I would expect this site to be patched a little before the patch is released, as any release needs to be tested befreo it goes out to the public.


Charles Nurse
DotNetNuke Trustee,
Senior Architect, DotNetNuke Coporation
MVP (ASP.NET) and
ASPInsiders Member
View my profile on LinkedIn
See my Blog for Articles on .NET, DNN and Module Development

View my Blog
 
New Post 5/23/2008 10:37 AM
User is offline Alex Shirley
2189 posts
5th Ranked




Re: PowerDNN Security Hotfix 

I can't freeze this post, but I would strongly recommend everybody stick to the thread (URL below) for further comment, to save everybody repeating themselves:

http://www.dotnetnuke.com/Community/Forums/tabid/795/forumid/118/threadid/228767/scope/posts/Default.aspx

 


Well might as well promo one of my DNN sites as I'm here: http://www.snasty.co.uk
 
New Post 5/23/2008 10:47 AM
User is offline Bill Yonder
12 posts
10th Ranked


Re: PowerDNN Security Hotfix 

Regardless of what the PowerDNN securtiy scanner says, I've been talking to some people in this forum and have gotten more details on the issue.  I tried going to the insecure page on DotNetNuke.com and it has been fixed.

Where's the patch for the community?  You guy's can't patch your stuff and leave the rest of us vulnerable!

Bill

 
New Post 5/23/2008 11:02 AM
User is offline Sebastian Leupold
15213 posts
www.deutschnetnuke.de
1st Ranked












Re: PowerDNN Security Hotfix 

 Bill Yonder wrote

Regardless of what the PowerDNN securtiy scanner says, I've been talking to some people in this forum and have gotten more details on the issue.  I tried going to the insecure page on DotNetNuke.com and it has been fixed. Where's the patch for the community.

Bill,

this has already been answered, please read previous posts carefully. Thank you.


Sebastian Leupold

DeutschNetNuke dnnWerk - The DotNetNuke Experts German DotNetNuke User-Group

DotNetNuke Project UserDefinedTable
DotNetNuke Project Release Tracker
 
New Post 5/23/2008 11:05 AM
User is offline Charles Nurse
2915 posts
5th Ranked










Re: PowerDNN Security Hotfix 

Bill - your response is evidence that supports our policy that "making security issues public exacerbates the situation".

You believe that we should have a fix and get it out - and are clamouring (almost panicing) for it.

To be responsible we cannot release any software - without fully testing it - do we have the right fix? will the fix have unexpected affects on other areas of the product? - is the fix itself secure?

All we received from PowerDNN after much delay was information on how the issue can be reproduced (we haven't received any information on how they fixed it for their own customers) - we then needed time to detemine the correct fix.

You would be complaining vociferously if we released a badly developed patch that caused other problems to your production sites?

If PowerDNN had not made this public - we could have spent more time on this issue - and less time trying to deal with the community panic/backlash.

Part of our testing process is to "dog-food" it on our properties - this is the responsible procedure.


Charles Nurse
DotNetNuke Trustee,
Senior Architect, DotNetNuke Coporation
MVP (ASP.NET) and
ASPInsiders Member
View my profile on LinkedIn
See my Blog for Articles on .NET, DNN and Module Development

View my Blog
 
Previous Previous
 
Next Next
  Forum  General DotNetN...  Chat About It!  PowerDNN Security Hotfix
 


Forum Policy

These Discussion Forums are dedicated to the discussion of the DotNetNuke Web Application Framework.

For the benefit of the community and to protect the integrity of the project, please observe the following posting guidelines:

1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DotNetNuke.
2. Discussion or promotion of DotNetNuke product releases under a different brand name are strictly prohibited.
3. No Flaming or Trolling.
4. No Profanity, Racism, or Prejudice.
5. Site Moderators have the final word on approving/removing a thread or post or comment.
6. English language posting only, please.

 


"SalarO" Skinning Graphic Design Branding Services
SalarO develops packaged & custom skins for your DNN at prices you can afford. SalarO is also developing Module development, Hosting, Branding/Logo design as well as Content Transfer Services to complement the core skinning solutions.
www.salaro.com
Data Springs Inc. - Module Development
Data Springs is a leader in the DNN community offering high quality modules, custom module development, enhancements to the DNN core product and overall DNN support.
www.datasprings.com
XCESS expertise center b.v.
Custom made modules and complete solutions for the DNN framework. Maatwerk modules en complete webtoepassingen gebaseerd op het DNN framework.
www.xcess.nl

DotNetNuke Corporation   Terms Of Use  Privacy Statement
DotNetNuke®, DNN®, and the DotNetNuke logo are trademarks of DotNetNuke Corporation
Hosted by MaximumASP