Small width layout Medium width layout Maximum width layout Small text Medium text Large text
     Search
Downloads Downloads Directory Directory Forums Forums Forge Forge Blogs Blogs        Marketplace Marketplace Careers Program Careers
News › Security Policy › Security Bulletin no.12 Register  |  

telerik -- supercharge your DNN websites
Validationkey can be a known value

Published: March 14, 2008

Version: 1.0

Maximum Severity Rating: Critical

Background

For the 3.0 release of DotNetNuke the security model was changed to use a validationkey to encrypt the forms authentication cookie and the viewstate. Under certain rare circumstances this key may not be updated during install/upgrade, and this information could allow a potential hacker the ability to access the portal as any user, including both the host and admin accounts.

Issue Summary

During installation of new releases, or upgrade of any release prior to 3.0, DotNetNuke automatically generates a unique validationkey to secure the users forms authentication cookie and viewstate. If this value is not updated, the "known" value can be used to access the portal. To install DotNetNuke the user must have write access to the root folder. For the validationkey to fail to be updated, the same user must fail to update this file i.e. either not have write permissions to it or else the file is set as "read only".

Mitigating factors

This issue will only manifest under a reasonably rare set of permissions.

Affected DotNetNuke versions

  • All versions since 3.0.

Non-Affected Versions:

  • All other versions

Fix(s) for issue

1. To fix this problem, you are recommended to update to the latest version of DotNetNuke (4.8.2 at time of writing)

2. Check your web.config file. If the validationkey value is not set to "F9D1A2D3E1D3E2F7B3D9F90FF3965ABDAC304902" then your portal does not suffer from this issue.

Acknowledgments

Brian Holyfield - Gotham Digital Science

Security Policy


Click here to read more details on the DotNetnuke Security Policy

 


Live Visitor Tracking & Live Chat For DotNetNuke
Track your visitors in real time and add live chat for sales & support. Free Trial.
www.whoson.com
SINA101
WANT A SPECial sIte iN TAIWAN?
sina101.com
Web Development and Strategy Firm
The Risdall Interactive Agency s websites, strategies, branding, & promotion in digital space.
www.Risdall.net/

DotNetNuke Corporation   Terms Of Use  Privacy Statement
DotNetNuke®, DNN®, and the DotNetNuke logo are trademarks of DotNetNuke Corporation
Hosted by MaximumASP