Security problem :/ (kind of) but it led to someone defacing one of my sites.

Last post 09-22-2004 12:02 AM by TimTimTimTim. 2 replies.

Sort Posts:

  • Security problem :/ (kind of) but it led to someone defacing one of my sites.

    09-19-2004, 2:45 AM
    • Member
      115 point Member
    • adfaddotcom
    • Member since 09-13-2004, 3:24 PM
    • Posts 23

    yes it's true i'm new to dnn, and yes it's true I make mistakes. However, I'm rather embarrased because I pride myself in being a software user/developer of almost 7 years.



    Because i'm so used to quickly learning software interfaces, I made a terrible mistake with DNN.


    Tonight one of my DNN websites was completely defaced. I logged on to find several oddball tabs along with a ton of deleted content from a customer that actually purchased a product from me and was upset that they didn't receive the product yet because they paid with a paypal e-check.



    Let me explain why I made this mistake. Please don't label me as a moron after this because it is a completely re-doable mistake by anyone. (ok maybe just happened to me)



    As a new user of DNN, while editing the security roles for modules, I quickly learned how to accomplish the task.


    The interface for setting up module security roles is setup in this way:
    Manage Viewers
    Manage Admins

    ""HOWEVER""
    I took my "newly learned knowledge" and applied it to the tab security roles.

    The security roles for tab pages are setup in this way:
    Manage Admins
    Manage Viewers

    So, what I did was give any user of the group that the defacer was in, the ability to edit whatever tabs I had assigned them to. Because both the security interfaces aren't in the same order, I simply use them as if they were.

    Brilliant on my part, simply brilliant. Now I think this is an isolated incident and may not have ever happened before. Or it could be because of the way things are set up in the interface, whereas both are vice-versa, that another new user could do the same thing I accomplished.


    As a final note, I would like to express my deepest graditude for the people that created the "RECYCLE BIN" and "LOG VIEWER" built-in modules. They have partially saved me from what would otherwise be a very intense migraine headache.
  • Re: Security problem :/ (kind of) but it led to someone defacing one of my sites.

    09-21-2004, 8:43 PM
    • Member
      490 point Member
    • DaveNuke
    • Member since 01-08-2004, 11:42 PM
    • Cairns, Australia
    • Posts 98
    No you’re not alone. It is a bit confusing.

    When I add a new tab or module I still log in as a user of each role to double-check that the correct permissions have been set. This may seem like a time consuming and boring job but when security is paramount it just has to be done.
  • Re: Security problem :/ (kind of) but it led to someone defacing one of my sites.

    09-22-2004, 12:01 AM
    • Participant
      1,250 point Participant
    • TimTimTimTim
    • Member since 08-23-2004, 11:47 PM
    • Posts 250

    Ahh..

    I think I'm going to edit the core DNN stuff and remove the ability for "All Users" to have administrative access to _anything_.
Page 1 of 1 (3 items)