Skip to content
Register
Login
Home
iFinity
Home
Services
Software Development
Website Development
DotNetNuke Consulting
Contracting Work
Products
Url Master
Product Details
Reviews and Testimonials
Pricing and Licences
FAQ
Downloads
Blog Module Url Provider
News Articles Url Provider
Tagger
FAQ
Downloads
Product Details
Instruction Video
Free Downloads
Inline Link Master
Product Details
FAQ
Support Forums
Knowledge Base
Url Master
News Articles Friendly Url Provider
Tagger
Contact
Blog
Licensing
Support
iFinity Blogs
Search
Fixing ASP.NET Security Vulnerability in a DotNetNuke Install
By Bruce Chapman on
Monday, September 20, 2010 4:19 PM
Scott Guthrie posted about an
important ASP.NET security vulnerability
over the weekend. If you have a DotNetNuke website, this vulnerability affects you, so take the time to read this and check if your site might be affected.
So far there has been no patch for the operating system, but there is a workaround which is very simple.
Basically, the vulnerability is that malicious users can probe your site and, from certain error codes, can break the cryptography securing important files like your web.config file.
The fix involves updating your website to provide a generic error page for all server errors. Many people will already have such a setup in place, although others (like me) might have left more descriptive error messages switched on for working out what has gone wrong.
Update [21st September] : DotNetNuke has an official post out on this one, so I think take...
Read More »
Comments (2)
Crafty Code
Clean out the tables from a DotNetNuke Database
By Bruce Chapman on
Wednesday, September 08, 2010 2:37 PM
Every now and again I get a failed DNN installation with a half-created database. When that happens, the best course of action is to clean out the database and start again with the install, making sure the problem is fixed. But how do you clean out the database?
Here’s a quick script I wrote to do this – to be run through a Sql query tool.
Note : don’t ever run this unless you want to actually destroy your DotNetNuke database. It’s a scorched earth deletion. It’s the Sql equivalent of delete *.* in old DOS days – except Sql Server won’t give you an ‘Are you sure?’ prompt.
Here’s the script:
declare @tableName nvarchar(100), @sql nvarchar(255) declare drop_curs cursor for select Name from sysobjects where type = 'u' and (name like 'dnn_%' or name like ‘aspnet_%’) open drop_curs fetch from drop_curs into @tablename while @@fetch_status = 0 begin select @sql = 'drop table ' + @tablename execute (@sql)...
Read More »
Comments (2)
Crafty Code
Hi, I'm Bruce Chapman, and this is my blog. You'll find lots of information here - my thoughts about business and the internet, technical information, things I'm working on and the odd strange post or two.
Share this
Get more!
Subscribe to the Mailing List
Email Address:
First Name:
Last Name:
You will be sent a confirmation upon subscription
Follow me on Twitter
Follow @brucerchapman
Stack Exchange
Klout Profile
Page Tags
301
content
domain
DotNetNuke
Duplicate
Redirects
Archive
<
September 2010
>
Sun
Mon
Tue
Wed
Thu
Fri
Sat
29
30
31
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
1
2
3
4
5
6
7
8
9
Monthly
January, 2012 (1)
December, 2011 (3)
November, 2011 (5)
October, 2011 (7)
September, 2011 (2)
July, 2011 (6)
June, 2011 (2)
May, 2011 (1)
March, 2011 (3)
February, 2011 (2)
January, 2011 (3)
December, 2010 (1)
November, 2010 (4)
October, 2010 (2)
September, 2010 (2)
August, 2010 (2)
July, 2010 (1)
June, 2010 (4)
May, 2010 (2)
April, 2010 (1)
March, 2010 (3)
February, 2010 (3)
January, 2010 (4)
December, 2009 (1)
October, 2009 (1)
September, 2009 (3)
August, 2009 (1)
July, 2009 (2)
June, 2009 (3)
May, 2009 (3)
April, 2009 (1)
March, 2009 (2)
February, 2009 (3)
January, 2009 (2)
November, 2008 (4)
October, 2008 (2)
August, 2008 (2)
July, 2008 (2)
June, 2008 (3)
May, 2008 (2)
April, 2008 (3)
March, 2008 (5)
February, 2008 (5)
September, 2007 (1)
August, 2007 (2)
July, 2007 (1)
June, 2007 (1)
November, 2006 (1)
October, 2006 (4)
August, 2006 (1)
July, 2006 (1)
June, 2006 (3)
Go
All Blogs
Bruce's Blog
Crafty Code
Keywords
Phrase