codebeater

General .NET, ASP.NET, C# and VB.NET discussion

About the author

Author Name is someone.
E-mail me Send mail

Recent comments

Authors

Disclaimer

The opinions expressed herein are my own personal opinions and do not represent my employer's view in anyway.

© Copyright 2009

BlogEngine.NET 1.3.0.0 Security Hole

As I mentioned here, codebeater was hacked over the weekend. Apparently, there was a flaw that would allow username and passwords to be viewed in plain text by simply viewing a specific url.  I am very disappointed to learn that this information is being stored in it's raw form in BlogEngine.NET.  However, kudos to the BlogEngine team for responding to the flaw as quickly as they did.  Unfortunately, I received word of the fix a little too late.  My site had not only been defaced but all content had been deleted. 

If you are using BlogEngine.NET 1.3.0.0 please update your site to the latest version immediately.  You can read more about this exploit here.

P.S.  I've restored much of my previous data, although it does not appear in it's proper chronological order.

Be the first to rate this post

  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Categories: .net | News
Posted by Jeff on Sunday, April 27, 2008 11:06 PM
Permalink | Comments (3) | Post RSSRSS comment feed

Related posts

Comments

oyun

Thursday, October 16, 2008 1:00 PM

oyun

Thanks the for article

Busby SEO TEST us

Wednesday, December 17, 2008 5:11 AM

Busby SEO TEST

Has this problem being solve? it kind of scary if people can read our confidential info

Busby SEO Test us

Thursday, December 18, 2008 10:21 PM

Busby SEO Test

it so interesting

Add comment


(Will show your Gravatar icon)  

  Country flag

[b][/b] - [i][/i] - [u][/u]- [quote][/quote]



Live preview

Tuesday, January 06, 2009 8:47 PM