Critical Security Fix for BlogEngine.net

by JoeStagner 4/14/2008 8:02:14 PM

BlogEngine.NET

Today, while sitting in a discussion about the new Microsoft MVC Framework at the Microsoft MVP summit, I got an email (reading on my phone) from Kevin Karasinski, a developer at Sandcastle Interactive.

The subject line of the email was my blog password !

Kevin sure knows how to get a guys attention :)

Kevin, good guy that he is, was taking the time to let me know about a newly discovered (and already fixed) security defect in BlogEngine.net, which is the blogging engine that I use here at JoeOn.net. 

Thanks Kevin, you gave me a freakin' heart attack !!!!

Needless to say, my blog has been patched to remove the defect.

Kevin pointed me to Danny Douglass' blog entry HERE.

And [ HERE ] is the official BlogEngine.net patch announcement.

Kudos to Danny, and the BlogeEngine.net guys for fixing this so quickly.

And thanks to Kevin for taking the time to let me know, though maybe next time you can just call my cell phone :)

Currently rated 5.0 by 9 people

  • Currently 5/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Tags:

ASP.NET | Joe Stagner [Syndicated] | Partners & Products

Related posts

Comments

4/14/2008 10:20:56 PM

Thank you for the dissemination.

sakamoto jp

4/15/2008 9:11:57 AM

Too funny. I'm going to have to look into implementing BlogEngine.net or one of the other engines soon.

Jason us

4/16/2008 1:18:37 PM

Pingback from weblogs.asp.net

Problema Serio de Seguridad en BlogEngine.net - DotNetMania@GT

weblogs.asp.net

4/16/2008 1:21:13 PM

Pingback from carloslone.wordpress.com

Problema Serio de Seguridad en BlogEngine.net « Blog de Carlos Lone

carloslone.wordpress.com

4/18/2008 2:18:50 PM

Pingback from cs2007.websitemagazine.com

Critical Security Fix for BlogEngine.net - Website Magazine - Website Magazine

cs2007.websitemagazine.com

4/22/2008 10:33:28 AM

prm._doPostBack('UpdatePanel1', '');
it works fine on the single page.But if added to page in a master page then it will do full page postback. Any idea how to fix it

thanks

jay us

4/23/2008 11:53:00 AM

Exelent!

Codes Web ar

Powered by BlogEngine.NET 1.3.0.0
Theme by Mads Kristensen

About your host.

Name of author Joe Stagner
?????

E-mail me Send mail

Calendar

<<  October 2008  >>
MoTuWeThFrSaSu
293012345
6789101112
13141516171819
20212223242526
272829303112
3456789

View posts in large calendar

Pages

Recent comments

Disclaimer

The opinions expressed herein are my own personal opinions and do not represent my employer's view in anyway.

© Copyright 2008

Sign in