11.21.2008
Register     Login      
 
DotNetNuke Platinum Benefactor

We're happy to show our support for the DotNetNuke platform and community by contributing back to the project at the highest "Platinum" level.
Testimonials
Wow, that was a fast response! Much appreciated. What you suggested did the trick. Thanks and a job well done on XMod. It's really been a ground-breaker on my recent DNN projects.
kflores (via our forums)
Urgent: Test Your DotNetNuke Site Now for Numerous Security Vulnerabilities
Location: BlogsBuck Anderson    
Posted by: Buck Anderson 5/23/2008 3:56 PM
According to Tony Valenti, CEO of Powerdnn.com a leading DotNetNuke hosting company, PowerDNN technicians have just discovered numerous security vulnerabilities in DotNetNuke core software...

According to Tony Valenti, CEO of Powerdnn.com a leading DotNetNuke hosting company, numerous security vulnerabilities have been recently detected in DotNetNuke core software.

Your site may be vulnerable to the following attacks:

  1. Administrator account permission escalation - A security vulnerability that could allow an admin user to upload a file to allow full Host acccess to the portal.
  2. Validationkey can be a known value - Under a rare set of circumstances, your website will encrypt data using a known-default key.
  3. Ability to create dynamic scripts on server - A security vulnerability that would allow server-side execution of server-side application logic.
  4. Any Website Viewer can Alter your web.config - A security vulnerability in DotNetNuke exists that allows any website visitor to alter your web.config file.
  5. Any Website Viewer can execute SQL Scripts on your Database - A security vulnerability in DotNetNuke exists that allows any website vistor to run SQL commands against your DotNetNuke database. This can result in complete site corruption.

I am running all of our sites on dedicated servers at PowerDNN and have been assured that the patch is being applied to all PowerDNN hosting customers.

If your are concerned about your site, I will post a link on DNNprofessor.com on Wednesday the 21st  to run the PowerDNN security scanner to see if your site is susceptible. You do not need to be a PowerDNN client to run the security scan.

Until we hear from the DotNetNuke core team, it is better to be safe than sorry.

I will be keeping up on this situation and post new information on DNNprofessor.com as it becomes available.

Buck Anderson

Copyright ©2008 Buck Anderson and DNNprofesor.com
Permalink |  Trackback

Your name:
Title:
Comment:
Security Code
Enter the code shown above in the box below
Add Comment   Cancel 
       Terms Of Use      Privacy Statement      © 2004-2008 Kelly Ford