By cathal connolly on
Friday, May 18, 2012 8:30:17 AM
One of the exciting enhancements coming in DotNetNuke 6.2.0 is the new Services Framework – a great way to write web services that integrate well with DotNetNuke. There’s a few blogs recently published that contain...
|
By cathal connolly on
Thursday, March 15, 2012 12:15:58 PM
|
By cathal connolly on
Thursday, February 02, 2012 4:12:59 PM
|
By cathal connolly on
Friday, December 30, 2011 8:10:47 PM
On Thursday 29th December 2011 Microsoft released an out-of-band security update to address an issue with asp.net . This is a relatively rare thing as Microsoft typically only releases security updates every 2nd Tuesday of the month (known as “ Patch Tuesday”) so it indicates that this is a serious issue that Microsoft does not want to leave available for exploitation for another few weeks. The advisory can be read here...
|
By cathal connolly on
Friday, December 23, 2011 7:24:04 PM
The 5.6.6 and 6.1.2 CE and PE versions of DotNetNuke have been released. The 6.1.2 release notes can be read @ DotNetNuke 6.1.2 Released . It contains two security fixes that resolve two “low” items. The 5.6.6 release only contains these two security fixes (as per our Sunsetted releases policy which can be read here ). The bulletins for the two items fixed in both...
|
By cathal connolly on
Wednesday, November 02, 2011 11:47:19 PM
The 5.6.4 and 6.1.0 CE and PE versions of DotNetNuke have been released. The 6.1.0 release notes can be read @ DotNetNuke 6.1.0 Released . It contains two security fixes that resolve one “low” and one “medium” issues. The 5.6.4 release only contains security fixes (as per our Sunsetted releases policy which can be read here ). The 5.6.4 release also contains 1 outstanding “low”...
|
By cathal connolly on
Thursday, July 07, 2011 1:03:58 AM
|
By cathal connolly on
Thursday, January 20, 2011 9:49:19 PM
|
By cathal connolly on
Thursday, November 25, 2010 11:05:14 PM
The 5.6.0 CE and PE versions of DotNetNuke have been released. The release notes can be read @ DotNetNuke 5.6.0 Released . This release contains a fix for one "low" security issue. The bulletin can be read at Exception details may leak if logging provider is unavailable ( DNN 2010-13-L) As always we recommend you upgrade as soon as possible. If you're new to upgrading I recommend...
|
By cathal connolly on
Wednesday, October 06, 2010 8:58:00 PM
As some of you may know, last Friday we noticed some unexpected user activity on our site. Further checking showing that some administrative accounts had been compromised via the recent asp.net padding oracle issue. As this exploit allows a hacker to crack the machinekey values, it's extremely serious as these are (amongst other things) part of what's used to secure user passwords.
The fix for this issue only came out midweek and we were still in the process of applying it, so we took the somewhat unprecedented...
|
By cathal connolly on
Tuesday, October 05, 2010 6:03:25 PM
The DotNetNuke Wiki has been in place for a little while now, and is starting to grow as more people discover it. We’re hoping that it’s growth will start to accelerate, and the reference team are committed to making efforts to ensure it becomes a valuable, relevant place to look for help. If you haven’t had a chance to look at it yet, please visit http://wiki.dotnetnuke.com/ (and while you’re there consider adding to it). I plan on blogging regularly...
|
By cathal connolly on
Friday, October 01, 2010 8:23:35 PM
A few days ago we alerted the community to the existence of a permanent fix from Microsoft to the oracle padding issue. At that point the fix was only available via Microsoft downloads, but now it’s available via Windows Update. This has the advantage of Windows update identifying and applying the fix for all necessary versions of the framework installed. We recommend all DotNetNuke sites apply this fix as soon as possible to resolve this issue permanently. Further details on the out-of-band release...
|
By cathal connolly on
Tuesday, September 28, 2010 8:15:00 PM
|
By cathal connolly on
Saturday, September 18, 2010 5:55:00 PM
A critical serious vulnerability in asp.net was publically disclosed late Friday at a security conference. We recommend that all users immediately apply a workaround (described below) to prevent attackers from using this vulnerability against your DotNetNuke (and any other ASP.NET) applications.
|
By cathal connolly on
Thursday, September 16, 2010 8:00:00 PM
Over the past few days we've had a number of community members send us links to various reports of a potential problem with the encryption of asp.net forms authentication. At this point there is very little information in the public domain about the specifics of it. We're been in contact with both of the authors of the original report, and are also working to gather as much relevant information as we can. If the issue is validated (Microsoft at this point have issued no public comment), we'll be well placed to see if there is anything we can do to mitigate the issue for DotNetNuke users. ...
|
By cathal connolly on
Wednesday, August 18, 2010 10:19:00 PM
|
By cathal connolly on
Thursday, June 17, 2010 4:02:00 PM
The 5.4.3 CE and PE versions of DotNetNuke have been released. These releases include fixes for a number of "low" and "medium" security issues.
|
By cathal connolly on
Tuesday, May 25, 2010 10:07:00 AM
The 5.4.2 CE and PE versions of DotNetNuke have been released. These releases include fixes for 2 "low" security issues.
|
By cathal connolly on
Thursday, February 18, 2010 4:03:00 PM
|
By cathal connolly on
Tuesday, February 02, 2010 12:47:00 AM
At the start of every year I like to do a quick roundup of some of the activities the security team have been up to. In general the better job we do, the less anyone hears about it, but rest assurred that we've busy working away to ensure DotNetNuke is as secure as possible and to help out anyone who's concerned their site may have been hacked.
|
By cathal connolly on
Saturday, November 28, 2009 2:40:00 PM
For anyone installing DotNetNuke on Windows 7/Windows 2008 RC2, theres been a subtle change in the default user used.
|
By cathal connolly on
Thursday, November 26, 2009 9:25:00 AM
|
By cathal connolly on
Friday, September 11, 2009 6:37:00 PM
The DotNetNuke security team would like to give a long overdue public welcome to our newest team member, Brandon Haynes.
|
By cathal connolly on
Wednesday, September 02, 2009 9:38:00 PM
|
By cathal connolly on
Thursday, May 21, 2009 12:38:00 PM
The 4.9.4 CE and PE versions of DotNetNuke has been released.
|
By cathal connolly on
Monday, May 18, 2009 3:52:00 PM
|
By cathal connolly on
Friday, January 02, 2009 8:17:00 PM
|
By cathal connolly on
Wednesday, September 10, 2008 11:21:00 PM
The 4.9.0 version of DotNetNuke has been released.
|
By cathal connolly on
Monday, June 30, 2008 11:58:00 PM
I've blogged before about how to make timeouts work correctly for persistent cookies, but thought I should also flag up a minor, but often requested, enhancement that will be in DotNetNuke 5.0. Whilst persistent cookies are useful for a lot of sites in some cases they're not approriate. Sites that require a higher level of security such as many financial, insurance, government or ecommerce sites often do not want to...
|
By cathal connolly on
Thursday, June 26, 2008 1:18:00 AM
|