Small width layout Medium width layout Maximum width layout Small text Medium text Large text
     Search
Downloads Downloads Directory Directory Forums Forums Forge Forge Blogs Blogs        Marketplace Marketplace Careers Program Careers
Community › Forums Register  |  

Affordable ASP.NET Hosting Service
  Need Help?  
Professional technical support for DotNetNuke is available from DotNetNuke Corporation.
 


  Ads  
Webhost4Life - $4.95 Windows Hosting
 


  Sponsors  

Meet Our Sponsors

FCKeditor Project
Salaro -- Skins and more
OnyakTech
The best choice for your web site host, email hosting, and domain registration.
CrystalTech Web Hosting™
Webhost4life, specialists in DNN hosting
 


DotNetNuke Forums
 
  Forum  DotNetNuke® Pro...  FCKeditor Provi...  Does FCKeditor have a BadWords.txt file?
Previous Previous
 
Next Next
New Post 4/25/2008 7:23 PM
User is offline barry zett
6 posts
1usa.com
10th Ranked


Does FCKeditor have a BadWords.txt file? 

Does FCKeditor have a BadWords.Txt file that an admin can add lines to?
When a user hits the Save button... it should check to see if any of the words are listed in the BadWords.Txt file.
If there is currently no way to control content, then websites are at risk.

The comment  made elsewhere "Make sure your portal permissions are configured appopriately so that only trusted users can enter content"
is the ostrich putting her head in the sand, and not a suitable solution for DNN websites, either business or hobby.

Thurs Apr 24, 2008
Dept of Homeland Security, UN, and UK's Dept of Civil Service were hacked, among 173,000 others.
and
 
If you do not receive these Security
 
New Post 4/26/2008 3:47 AM
User is offline Sebastian Leupold
13707 posts
www.deutschnetnuke.de
1st Ranked












Re: Does FCKeditor have a BadWords.txt file? 

No, FCKEditor does not filter any input, this is subject of the modules. Forums uses a bad words filter to avoid offending words, besides modules are adviced, to filter scripts (there is a core function to be used to do this) and htmlencode any text input from non-admins. Anyhow, this is not connected with the SQL injection, mentioned in the articles you linked to, since all modules shall use vulnarable stored procedures to communicate with the database, and at least DNN core and all core modules do this (and this is verified during security review as part of the release tracking process, every core module has to pass before being published or added to the DNN package).


Sebastian Leupold

DeutschNetNuke dnnWerk - The DotNetNuke Experts German DotNetNuke User-Group

DotNetNuke Project UserDefinedTable
DotNetNuke Project Release Tracker
 
New Post 4/26/2008 7:49 AM
User is offline Brandon Haynes
542 posts
everysport.net
8th Ranked


Re: Does FCKeditor have a BadWords.txt file? 

Hi Barry,

Sebastian is right (as usual).  Despite the many, many (many!) public DotNetNuke installations out there, with all the myriad configurations, I am aware of only two that have been hit with the nihaorr1 injection.  Both of these are virtually certainly affected via third-party modules and cross-application contamination.  Of those two pathways of infection, the latter is the overwhelmingly more likely to be the cause.

The real morale of the story here: move your weak legacy ASP.NET applications to DotNetNuke, and you no longer have to worry about this particularly insidious injector!

Sebastian: I know you require all-SPs to pass the release process.  However, I recall seeing the use of the EXEC statement in a couple of these SPs (I believe I logged one of them in Gemini).  As this could be a backdoor avenue of infection, have you considered disallowing this particular statement from SPs that go through the release process?

Brandon


Brandon Haynes
BrandonHaynes.org
 
New Post 4/26/2008 8:52 AM
User is offline Sebastian Leupold
13707 posts
www.deutschnetnuke.de
1st Ranked












Re: Does FCKeditor have a BadWords.txt file? 

HI Brandon,

thanks for the applause - but of course, there are a number of posts, where even I had to learn from other experts.

Regarding the release process, all reviews are done by our Security Experts, mainly Cathal, whose Hacker Brain usually detects all common and uncommon scenarios. I am aware, that there are SPs using Exec, but most of them need to do so to cover dynamic data structures not processing parameters they have been called with and AFAIK none of them do get passed user input, which would be the door for SQL injection (if you though have a module, where you fear such a risk, please send the information to security@dotnetnuke.com in order to get it checked by our security team, thank you!)

Have a nice WE!


Sebastian Leupold

DeutschNetNuke dnnWerk - The DotNetNuke Experts German DotNetNuke User-Group

DotNetNuke Project UserDefinedTable
DotNetNuke Project Release Tracker
 
New Post 4/26/2008 11:12 AM
User is offline Brandon Haynes
542 posts
everysport.net
8th Ranked


Re: Does FCKeditor have a BadWords.txt file? 

Yep -- as my Saturday homework, I just checked, and there are no relevant instances of sp_executeql calls in the core or the common modules that I happen to have installed on my dev machine.  The one instance that I found and logged awhile back (http://support.dotnetnuke.com/issue/ViewIssue.aspx?id=5128&PROJID=22) is not a security issue.  I figured you guys already had a procedure in place for such an eventuality.

And of course I meant sp_executesql in my previous post and not EXEC.

Brandon


Brandon Haynes
BrandonHaynes.org
 
Previous Previous
 
Next Next
  Forum  DotNetNuke® Pro...  FCKeditor Provi...  Does FCKeditor have a BadWords.txt file?
 


Forum Policy

These Discussion Forums are dedicated to the discussion of the DotNetNuke Web Application Framework.

For the benefit of the community and to protect the integrity of the project, please observe the following posting guidelines:

1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DotNetNuke.
2. Discussion or promotion of DotNetNuke product releases under a different brand name are strictly prohibited.
3. No Flaming or Trolling.
4. No Profanity, Racism, or Prejudice.
5. Site Moderators have the final word on approving/removing a thread or post or comment.
6. English language posting only, please.

 


Jetkey Smart Map
Smart Map is an AJAX powered Google Map module that displays driving directions, proximity search results and data from your own databases. Smart Map reads GPX (GPS data) files, GeoRSS feeds, and KML data. You can pass any querystring parameter to Smart Map and into your own custom queries to control what data displays on the map.
smartmap.jetkey.com
DNNSpired.com
Inspired to extend DotNetNuke®, everyday.
www.DNNSpired.com
TMA Resources
TMA Resources is a software company providing eBusiness solutions for the Association market.
www.tmaresources.com

DotNetNuke Corporation   Terms Of Use  Privacy Statement
DotNetNuke®, DNN®, and the DotNetNuke logo are trademarks of DotNetNuke Corporation
Hosted by MaximumASP