> Forums > Active Social > General Discussion > Oracle Padding Vulnerability in ASP.NET and AS 404 vanity URLs
Last Post 22 Sep 2010 06:10 PM by mcove. 4 Replies.
AddThis - Bookmarking and Sharing Button Printer Friendly
  •  
  •  
  •  
  •  
  •  
PrevPrev NextNext
You are not authorized to post a reply.
Author Messages
Raymond
Customers
Raymond
Post Count:154

--
21 Sep 2010 09:07 AM
    If you are not aware, there has been a fairly significant security vulnerability found with Asp.Net that involves cryptography and custom errors. 

    You can find more information at these URLS:




    I am applying the suggested fixes, but the fix sends all errors to the same page that does not display the cause of the error. That is the purpose of the fix because the data around that information is the problem.

    My question is: How should we handle this with the different methods that Active Social uses to route vanity URLs for User Profiles and Groups?
    Will Morgenweck Forum Admin
    DotNetNuke Staff
    Will Morgenweck
    Post Count:7672

    --
    21 Sep 2010 11:46 AM
    I updated our sites over the weekend and didn't have any problems. We haven't tested the work around with vanity URLs and a custom 404.aspx page with IIS 6. I'm guessing that it will probably cause the vanity urls to fail. We are using vanity urls with the wildcard mapping and it is still working fine. However, given the severity of this vulnerability I would suggest applying the workaround ASAP and worry about vanity urls later. You may need to temporarily disable vanity urls, but that would be much better than having to deal with a compromised site.
    Will Morgenweck
    Director of Product Management
    DotNetNuke Corp.
    Raymond
    Customers
    Raymond
    Post Count:154

    --
    21 Sep 2010 11:57 AM
    I agree. I just wanted to be sure that there was not a work around for the vanity URLs.

    Thank you
    MHuijbregts
    Customers
    MHuijbregts
    Post Count:1248

    --
    22 Sep 2010 05:30 AM
    It seems like that hackers are indeed exploiting the security leak. Check out this MS blog post: http://blogs.technet.com/b/msrc/arc...16728.aspx

    I guess we'd better keep everyone informed and advise site owners to apply the web.config changes!!
    Regards,
    Marc
    www.biservices.eu for free nl-NL resourcepacks (Incl. Active Forums & Active Social)
    mcove
    Customers
    mcove
    Post Count:18

    --
    22 Sep 2010 06:10 PM
    Dotnetnuke 05.05.01 has been released. It includes the ASP.Net POET Vulnerability /Oracle Padding fix.
    You are not authorized to post a reply.
    > Forums > Active Social > General Discussion > Oracle Padding Vulnerability in ASP.NET and AS 404 vanity URLs
    test
    Copyright 2012 by DotNetNuke Corporation / Terms of Use / Privacy