Small width layout Medium width layout Maximum width layout Small text Medium text Large text
     Search
Downloads Downloads Directory Directory Forums Forums Forge Forge Blogs Blogs        Marketplace Marketplace Careers Program Careers
News › Security Policy › Security Bulletin no.8 Register  |  

Maximum ASP
Phishing risk in login redirect code

 

Published: July 18, 2007

Version: 1.0

Maximum Severity Rating: Medium

Background

DotNetnuke allows administrators to utilise a standard login page or create their own custom login page. When an unauthenticated user arrives at a site and attempts to access a protected resource they will be redirected to the correct login page. As part of this process the original request for the protected resource is remembered so that once the user has succesfully logged in, they can be redirected to the originally requested resource.

Issue Summary

The return path for the protected resource uses a querystring to store the url. This value is an implicitly trusted URL, so it is possible for a hacker to publish a url to your site that already contains this querystring parameter. In this case the hacker could point it to an untrusted source. A fix has been added to ensure that only paths relative to the website are supported.

Further information on phishing can be found here.

Affected DotNetNuke versions

  • All versions

Non-Affected Versions:

  • 4.5.4

Fix(s) for issue

To fix this problem, you are recommended to update to the latest version of DotNetNuke (4.5.4 at time of writing).

Acknowledgments

DotNetNuke thanks the following for working with us to help protect users:

Security Policy


Click here to read more details on the DotNetnuke Security Policy

 


WEBPC™ DotNetNuke® sites for Small Business
WEBPC™ are internet consultants and web hosters catering to the small business market.
www.webpc.biz
Perpetual Motion Interactive Systems Inc.
A solutions company specializing in Microsoft enterprise technologies.
www.perpetualmotion.ca
Icthus Technologies
Building Faith on the Internet
www.icthustech.com

DotNetNuke Corporation   Terms Of Use  Privacy Statement
DotNetNuke®, DNN®, and the DotNetNuke logo are trademarks of DotNetNuke Corporation
Hosted by MaximumASP