IBuySpy Portal and Portal Starter Kit Security Issue
Yesterday we became aware of a security vulnerability in two of our sample applications: the IBuySpy Portal and the Portal Starter Kit. We have temporarily removed the IBuySpy Portal sample download and are actively working on an update. An updated Portal Starer Kit sample (version 1.0b) is now available which fixes the problem for that sample.
This email provides the steps to immediately fix existing sites and mitigate the potential for a malicious attack.
Who is vulnerable?
-- Any version of the VB.NET IBuySpy Portal sample configured to use html forms authentication.
-- A...
IBuySpy Portal vs. Portal Starter Kit
I am new to portals and relatively new to ASP.NET and I would appreciate some clarification about IBS and the Portal Starter Kit.
I have read existing postings and come away with the impression that the Portal Starter Kit is a more updated version of IBS, which is not being further developed.
But then I notice a lot of developer activity on the forums for both IBS and Portal Starter Kit and Microsoft features both prominently and independently on the ASP.NET site.
I have been leaning toward IBS because I have the Wrox book Building an ASP.NET Intranet to guide my initial work in add...
When I deleted PortalCfg.xsd,the Portal Starter Kit can still work normally.Then What is the use of PortalCfg.xsd in Portal Starter Kit?
Thanks!
The purpose of PortalCfg.xsd is to make the layout and validate the PortalCfg.xml!
The struct of PortalCfg.xml is based on PortalCfg.xsdregards João Martins...
use portal starter kit with community starter kit
I am using the portalvbsdk and community starterkit but both have different user login database, is it possible to connect both starter kits with only one user login panel?
Sorry, I am very new with ASP.NET
I don't think so.
The permissions in portal are different than permissions in community. If a person only logs in one and not the other, the permission settings will always be wrong for the one which has no login.
...
I Buy Spy Portal vs Portal Starter Kit
There seems to be lots of confusion between the IBS Portal and the Portal Starter Kit. Lots of people publish quastions relating to the IBS here, and lots of people answer to questions about the Portal Starter Kit as if it was the IBS. It might be a good idea if a few people that are well familiar with both versions post some info as to the differences. This will help many not only with their confusion but also chose which one to use, based on these differences.
Thanks
When I started this thread I was sure it will be flooded with opinions and comparisons between IBS Portal and Portal St...
Portal Starter Kit #2
Hi guys,
I just downloaded the portal starter kit. I am newbie to .net programming therefore this is really tough yet impressive application.
Can someone tell me if there is any site that has a step by step tutorial for this application? The whitepaper dont explain much.
it would be really nice if someoene posted step by step tutorial so we can understand this much better.
Thanks
Manny
Open every page step by step and read the code.
thats funny...join the club...
Portal Starter Kit / .NET 2.0 Version / Web Client Software Factory Version
I have started to refactor the initial starter kit.
The database schema is still the same for compatibility reasons.
http://www.codeplex.com/ASPNETPortal
Features
Dynamic Portal Infrastructure
10 basic portal modules for common types of content
2 extra portal modules: RSS Feed and Wiki
A "pluggable" framework that is simple to extend with custom portal modules
Online administration of portal layout, content and security
XML based definition of portal layout
Database based definition of portal layout
Roles-based security for viewing content, editing content, ...
Differences between the Club Starter Kit, Club Starter Kit 2.0, and Extended Club Starter Kit
I'm a little confused as the the differences between these 3 starter kits, can someone point the differences out to me?Victor Corey
I picked the first one, because I thought that it would be the easiest and least complicated to understand and work with. I have the same question. You posted this some time ago, I guess nobody knows. I am only posting this so it will show up again, and maybe someone will address it. Thanks.
I don't know about the extended, but I worked with the Club Site Starter Kit for several days and got stuck when needing to actually get ...
Portal Starter Kit Security Problem
I have defined four levels of users, but the portal will not allow the appropriate ones Edit Access to the User Control under a particular tab. Everything looks peachy in the PortalCfg.xml file, so I'm mystified why it won't work.
This is very, very difficult to troubleshoot given the fact that everything is loaded dynamically from the PortalCfg.xml file in the DesktopDefault.aspx page!
Any hints, tips, tricks or other info is greatly appreciated.
Thanks, Darin
It might be an obvious answer...
Have you selected in each module you want the roles that can edit?Do you know the tr...
Database issue while installing Portal Starter Kit.
I have MSDE running on my local work-station under the machine name
(and not under 'localhost'). I am trying to install the ASP.NET Portal
Starter Kit (to be host under IIS on my machine). When it reaches the
step for database, I choose 'local' and then it comes with the dialog
box of 'Test Connection' with 'localhost' written in the drop-down.
This 'Test Connection' fails and as the drop down is non-editable, I
even cannot enter my machine name onto it. It exits the complete setup
there on. I next tried 'remote' database as installation option, but
because I do not have Query Analyz...
Application Security & Portal Starter Kit
The GetSingleContact function in the Components\Contact.vb folder of Portal Starter Kit, returns a DataReader with data from the GetSingleContact stored procedure.
I have read that it is good security practice to place any opening/execution of connections in a TRY block, and closing of connections in a FINALLY block. However due to a DataReader named "result" being returned, the connection must remain open as long as the DataReader is open? ("Dim result As SqlDataReader = myCommand.ExecuteReader(CommandBehavior.CloseConnection)")
Surely this poses a security conce...
How to do this in Portal Starter Kit
Hi, I designed a website (let's call it WebSiteA) using the Portal Starter Kit, one of the tabs is only visible to users that are logged in. Within this tab, I had a quick link or a button, when the user click on it, another website (WebSiteB) will be launched. That is no problem. The problem is if the user did not log in WebSiteA, he/she should not be allowed to view WebSiteB if he/she tried to launch WebSiteB directly from the web browser. How to implement this? I want to use Cookies, but not sure if this is the right solution. Any help is appreciated!
cookies could work or check th...
Portal starter Kit
I'm getting ready to use the Portal starter Kit to for a large school web site. Has anybody had any problems with the starter kits and if so what where they
I think they are all great solutions! I personally love the DotNetNuke portal and feel it is the most superior solution out there for several reasons:
1) there is a team of 30 programmers constantly developing future versions
2) there is a great community forum here (dotnetnuke forum) for help/support/questions
3) there are over 500 add-on modules available for almost any need - some are free and some are for money
4) ope...
Portal Starter Kit
I'm trying to download the portal starter kit, but I keep getting an error message from download.microsoft.com. Does anyone have the installer that I can download?
Thanks
Did you ever get it to download??No Animals were harmed in the making of the Application
Hammer12...