Small width layout Medium width layout Maximum width layout Small text Medium text Large text
     Search
Downloads Downloads Directory Directory Forums Forums Forge Forge Blogs Blogs        Marketplace Marketplace Careers Program Careers
Community › Forums Register  |  

AspDotNetStoreFront
  Ads  
Active Modules -- Active Forums for DotNetNuke
 


  Sponsors  

Meet Our Sponsors

SteadyRain
DataSprings - Great Ideas. Always Flowing.
R2integrated - formerly bi4ce
Jango Studios - Skins, Modules and Hosting for DotNetNuke
eUKhost.com is commited to offer exceptional UK Windows Web Hosting solutions with quality 24x7 technical support.Our plans support ASP.Net, ASP, ASP.NET Ajax extensions, XML, MSSQL, MySQL, PHP,DNN, multiple domains and Shared SSL as standard.
SmarterTools
 


DotNetNuke Forums
 
  Forum  General DotNetN...  Chat About It!  PowerDNN Security Hotfix
Previous Previous
 
Next Next
New Post 5/23/2008 4:55 PM
User is offline Charles Nurse
2915 posts
5th Ranked










Re: PowerDNN Security Hotfix 

 Bill Yonder wrote

In another post, charles said this issue has existed for 12-18 months!  I would expect that with something that has been around that long that they would already have an official patch. 

Being around for any period time does not mean we were aware of it.   The point we were making is that it was not a serious enough issue to go publicising it so widely without informing the deveopers of the software of the issue.

We take ALL security issues seriously - the problem with this is issue is that it was made public without any thought to the consequences, leaving us to deal with the backlash.

How would you like it if your neighbour put a sign outside of his house - saying - "I have a security system, but look on the back of this sign and you will see a list of all the houses in the neighbourhood that don't".


Charles Nurse
DotNetNuke Trustee,
Senior Architect, DotNetNuke Coporation
MVP (ASP.NET) and
ASPInsiders Member
View my profile on LinkedIn
See my Blog for Articles on .NET, DNN and Module Development

View my Blog
 
New Post 5/23/2008 5:23 PM
User is offline ROBAX
1875 posts
5th Ranked


Re: PowerDNN Security Hotfix 

 Bill Yonder wrote

When is that going to be?  Today?  Next week?  Next month?  Any ETA at all?

Bill

The whole point of the PowerDNN Security Scammer was that you can pay them to fix it for you and alleviate the fear that they so purposefully generated. I'm sure they'll still be perfectly happy to sort it out for you if you can't wait.

Rob

 
New Post 5/23/2008 5:50 PM
User is offline Shaun Walker
1455 posts
www.dotnetnuke.com
6th Ranked










Re: PowerDNN Security Hotfix 

I think there is a misconception in the community at the moment. What PowerDNN has referred to as a "patch" or "hotfix" for their customers is actually not a solution at all. Instead, it was a way of preventing a hacker from exploiting a security hole. In order to do this, PowerDNN simply removed some key functionality from all of their customer sites (ie. they deleted some files which provide some key content management functionality ). When they eventually reported the issue to us, it was in the form of an application which could be used to demonstrate the exploit. It was not a solution to the problem. PowerDNN offered no solution and instead relied on us to figure out the appropriate solution, implement it, test it, etc... Unfortunately, they gave us no actual time to accomplish this before they released a public press release announcing their findings. I have been quiet today as we focussed on solving the security problem. A 4.8.3 security release has been created. It solves the 2 issue which PowerDNN reported as well as another more serious security issue which was reported to us through proper channels ( and which PowerDNN as well as their customers are currently susceptible to ). Once we have the opportunity to run a few more tests, we will be making the 4.8.3 security release available to the entire community. I will not be making any more forum posts about this topic until this occurs. Thank you for your patience and professionalism.


Shaun Walker
President / Chief Architect
DotNetNuke Corporation
 
New Post 5/23/2008 6:32 PM
User is offline Michael Gerholdt
449 posts
8th Ranked


Re: PowerDNN Security Hotfix 

 Bill Yonder wrote

When is that going to be?  Today?  Next week?  Next month?  Any ETA at all?

Bill

 

Good Golly Miss Molly Bill Yonder -

Give it a break. Obviously they're workin' on it.

Our good friends in DNN core-ville are maybe not so good at controlling themselves when their blood's up and someone's done them wrong ... but they have an excellent track record when it comes to getting the technical job done. And the "policy and procedure" side has matured nicely. I find the comment about a 'known' issue for 18 months rather disconcerting, too, but hey ... Let them be and let's move on. We can look for answers to that one after the dust has settled.

At this level, you don't just slap a couple-three lines of code into a procedure and throw it out to the public. Regression testing takes real time. Be thankful they are willing to spend that time in spite of those who clamor for immediate gratification ... nobody's perfect, but they do know what they're doing.

DNN core: I suggest that you identify a media spokesperson - someone who is good at the language, good with people, and who will act as the 'mouth' of DNN core in situations like this. Not to muzzle all the rest of you, and certainly we do want to know what you all think - it's great and instructive reading, and very important information besides  - but in the midst of the situation, it is NOT helpful to have everybody putting out equally official or non-official statements ... let one person or one small team handle the PR. AS LONG as they provide good, substantive and frequently released information ... we'd probably all benefit.

It's probably an inevitable step in the maturity curve anyway. Would have stood us in good stead though this debacle.


pmgerholdt
 
New Post 5/23/2008 7:20 PM
User is offline Will Morgenweck
224 posts
www.activemodules.com
9th Ranked






Re: PowerDNN Security Hotfix 

 Michael Gerholdt wrote

 Bill Yonder wrote

 

When is that going to be?  Today?  Next week?  Next month?  Any ETA at all?

Bill

 

 

Good Golly Miss Molly Bill Yonder -

Give it a break. Obviously they're workin' on it.

Our good friends in DNN core-ville are maybe not so good at controlling themselves when their blood's up and someone's done them wrong ... but they have an excellent track record when it comes to getting the technical job done. And the "policy and procedure" side has matured nicely. I find the comment about a 'known' issue for 18 months rather disconcerting, too, but hey ... Let them be and let's move on. We can look for answers to that one after the dust has settled.

Instead of assuming the worst, we should just take a little more time to understand exactly what was said.  Charles never said it was a "known" issue for 18 months.  He said it existed.  There is a big difference.  PowerDNN was the first to find the exploit, there is no disputing that fact.  I believe the point that Charles has been trying to make is that the code that introduced this issue was created many months ago.  This means that it has been in the application for several releases.  I believe Shaun has also stated, that even though this issue was present, DotNetNuke still passed numerous third-party security audits. 

Why is it so difficult to understand that had this been handled properly, it would still be business as usual for the DotNetNuke Community.  We all would have been properly patched and probably sooner had the Core not had to deal with all this chaos, or even better, notified promptly. 


Will Morgenweck
Active Modules, Inc.
Social Networking and Community Solutions for DotNetNuke
Active Social - Stop by our booth at Open Force for a demo
www.activemodules.com
 
Previous Previous
 
Next Next
  Forum  General DotNetN...  Chat About It!  PowerDNN Security Hotfix
 


Forum Policy

These Discussion Forums are dedicated to the discussion of the DotNetNuke Web Application Framework.

For the benefit of the community and to protect the integrity of the project, please observe the following posting guidelines:

1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DotNetNuke.
2. Discussion or promotion of DotNetNuke product releases under a different brand name are strictly prohibited.
3. No Flaming or Trolling.
4. No Profanity, Racism, or Prejudice.
5. Site Moderators have the final word on approving/removing a thread or post or comment.
6. English language posting only, please.

 


DNN SEO
Seablick Consulting specializes in DNN search engine optimization (SEO), DNN consulting, as well as support & training.
seablick.com
Intura Vision / Intura Enterprise
Point-of-Sale and business management applications targeted towards quick service, fast casual and delivery-based restaurant concepts.
www.intura.com
Dnaxp.Net
Dnaxp.Net offers a comprehensive base of information, resources, and support for DotNetNuke.
www.dnaxp.net

DotNetNuke Corporation   Terms Of Use  Privacy Statement
DotNetNuke®, DNN®, and the DotNetNuke logo are trademarks of DotNetNuke Corporation
Hosted by MaximumASP