HomeHomeOur CommunityOur CommunityCommunity Membe...Community Membe...Any PowerDNN users? Any PowerDNN users?
Previous
 
Next
New Post
5/21/2008 10:41 AM
 

What the hell is going on here? Did PowerDNN discover a security vulnerability and not tell the DNN team about it?

And then charge $20 to fix it?

 


Chris
 
New Post
5/21/2008 11:02 AM
 

Seems like...


Web applications, DNN websites, modules, skins and support
 
New Post
5/21/2008 11:11 AM
 
What is confusing is whether the DNN team has been contacted or not. Nothing should have been mailed or posted until the DNN team had a chance to review and develop a fix. If indeed there is a vulnerability someone could see this post and the PowerDNN site and begin investigating how to exploit. If it were me I’d kill this thread completely and ask PowerDNN to remove the notice on their site until a fix is widely available to the entire community. Certainly they should apply a patch to their customer sites as needed but keep this under wraps until a fix is GA for all.
 
New Post
5/21/2008 11:20 AM
 

Hi Guys,

When we discovered this vulnerability, it was found to be such a critical issue that we were compelled to secure our customers right away.  Our first responsibility is always going to be to make sure that PowerDNN customers are running high performance, secure, DNN installations.  Our customers have been overwhelmingly thankful for the hard work we've done to secure their sites.  Our team is putting together an official report which we will release to the community, it is important that everyone is aware of the issue.  We have been in contact with certain members of the core team as well as many of the top vendors in the community.  In terms of the $20, we could take that away but then we wouldn't be able to patch non-PowerDNN customers in any way that would be financially feasible.  If we got rid of the $20 charge, we could scan your site but not perform any fix.  This issue effects so many sites that we want to protect community by releasing the information in a thoughtful way.  We will get the information out via the normal DNN channels, but, we view this issue as being critical enough that waiting until the next release of DNN is not sufficient and we were compelled to take action immediately.  I hope this clears some things up for some people, we take issues like this very seriously, because like most of you, we love DotNetNuke and it is our livelyhood. 

John Grange


PowerDNN DNN hosting
 
New Post
5/21/2008 11:22 AM
 

Tony Valenti wrote

Hey Dan,
We are working with the DotNetNuke Core Team to make this patch available to everyone.  We're not releasing the patch to the public as of yet because if the wrong people became aware of the flaw or its location, it would mean catastrophe for almost any non-PowerDNN customer who has set up DotNetNuke within the past year.

During this "Zero Day" time period, we are offering a service where our engineers will work with companies for virtually free to help them patch their mission critical websites while the DotNetNuke core team creates an "official" resolution to the issues.

I understand that you're really curious about what the flaw was, however, if you notice any changes, please hold back from discussing them.

Always glad to help,
-Tony Valenti

But what if malfeasants are able to come up with $20?  Are the PowerDNN engineers asking any trick questions to ensure that people buying the fix have good intensions? 

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityCommunity Membe...Community Membe...Any PowerDNN users? Any PowerDNN users?


Forum Policy

These Discussion Forums are dedicated to the discussion of the DotNetNuke Web Application Framework.

For the benefit of the community and to protect the integrity of the project, please observe the following posting guidelines:

1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DotNetNuke.
2. Discussion or promotion of DotNetNuke product releases under a different brand name are strictly prohibited.
3. No Flaming or Trolling.
4. No Profanity, Racism, or Prejudice.
5. Site Moderators have the final word on approving/removing a thread or post or comment.
6. English language posting only, please.

Attend A Webinar
Free Demo Site
Download DotNetNuke Professional Edition Trial
Have Someone Contact Me
Have Someone Contact Me
Charlotte DoDNN

Like Us on Facebook Join our Network on LinkedIn Follow DNN Corporate on Twitter Follow DNN on Twitter

Advertisers

DotNetNuke DNN Hosting
Exact Target Exec Alert
r2integrated

DotNetNuke Scoop!

Sponsors

DotNetNuke Corporation

DotNetNuke Corp. is the steward of the DotNetNuke open source project, the most widely adopted Web Content Management Platform for building web sites and web applications on Microsoft. Organizations use DotNetNuke to quickly develop and deploy interactive and dynamic web sites, intranets, extranets and web applications. The DotNetNuke platform is available in a free Community and subscription-based Professional and Enterprise Editions with an Elite Support option. DotNetNuke Corp. also operates the DotNetNuke Store where users purchase third party apps for the platform.