From aea299635ec3556dacfbc34d087af865000184a1 Mon Sep 17 00:00:00 2001
From: George Alatrash
Header: {0}", HttpUtility.HtmlEncode(headerValue));
- }
- if (!string.IsNullOrEmpty(footerValue))
- {
- note += string.Format("
Footer: {0}", HttpUtility.HtmlEncode(footerValue));
- }
- note += "< br />";
-
- result.Notes.Add(note);
+ note += string.Format("
Header: {0}", HttpUtility.HtmlEncode(headerValue));
}
- }
- catch (Exception)
- {
- throw;
- }
+ if (!string.IsNullOrEmpty(footerValue))
+ {
+ note += string.Format("
Footer: {0}", HttpUtility.HtmlEncode(footerValue));
+ }
+ note += "< br />";
+ result.Notes.Add(note);
+ }
return result;
}
}
diff --git a/Components/Checks/CheckPasswordFormat.cs b/Components/Checks/CheckPasswordFormat.cs
index e02c6f9..8998b14 100644
--- a/Components/Checks/CheckPasswordFormat.cs
+++ b/Components/Checks/CheckPasswordFormat.cs
@@ -1,7 +1,4 @@
-using System;
-using System.Web;
-using System.Web.UI;
-using DotNetNuke.Security.Membership;
+using DotNetNuke.Security.Membership;
namespace DNN.Modules.SecurityAnalyzer.Components.Checks
{
@@ -14,22 +11,15 @@ public class CheckPasswordFormat : IAuditCheck
public CheckResult Execute()
{
var result = new CheckResult(SeverityEnum.Unverified, Id);
- try
+ var format = MembershipProvider.Instance().PasswordFormat;
+ if (format == PasswordFormat.Hashed)
{
- var format = MembershipProvider.Instance().PasswordFormat;
- if (format == PasswordFormat.Hashed)
- {
- result.Severity = SeverityEnum.Pass;
- }
- else
- {
- result.Notes.Add("Setting:" + format.ToString());
- result.Severity = SeverityEnum.Failure;
- }
+ result.Severity = SeverityEnum.Pass;
}
- catch (Exception)
+ else
{
- throw;
+ result.Notes.Add("Setting:" + format.ToString());
+ result.Severity = SeverityEnum.Failure;
}
return result;
}
diff --git a/Components/Checks/CheckRarelyUsedSuperuser.cs b/Components/Checks/CheckRarelyUsedSuperuser.cs
index 9de4f72..30af2f3 100644
--- a/Components/Checks/CheckRarelyUsedSuperuser.cs
+++ b/Components/Checks/CheckRarelyUsedSuperuser.cs
@@ -1,6 +1,5 @@
using System;
using DotNetNuke.Entities.Users;
-using DotNetNuke.Security.Membership;
namespace DNN.Modules.SecurityAnalyzer.Components.Checks
{
@@ -13,26 +12,19 @@ public class CheckRarelyUsedSuperuser : IAuditCheck
public CheckResult Execute()
{
var result = new CheckResult(SeverityEnum.Unverified, Id);
- try
- {
- var totalRecords = 0;
+ var totalRecords = 0;
- var superUsers = UserController.GetUsers(-1, 1, int.MaxValue, ref totalRecords, false, true);
- result.Severity = SeverityEnum.Pass;
- foreach (UserInfo user in superUsers)
+ var superUsers = UserController.GetUsers(-1, 1, int.MaxValue, ref totalRecords, false, true);
+ result.Severity = SeverityEnum.Pass;
+ foreach (UserInfo user in superUsers)
+ {
+ if (DateTime.Now.AddMonths(-6) > user.Membership.LastLoginDate ||
+ DateTime.Now.AddMonths(-6) > user.Membership.LastActivityDate)
{
- if (DateTime.Now.AddMonths(-6) > user.Membership.LastLoginDate ||
- DateTime.Now.AddMonths(-6) > user.Membership.LastActivityDate)
- {
- result.Severity = SeverityEnum.Warning;
- result.Notes.Add("Superuser:" + user.Username);
- }
+ result.Severity = SeverityEnum.Warning;
+ result.Notes.Add("Superuser:" + user.Username);
}
}
- catch (Exception)
- {
- throw;
- }
return result;
}
}
diff --git a/Components/Checks/CheckSiteRegistration.cs b/Components/Checks/CheckSiteRegistration.cs
index af1e46e..4133c45 100644
--- a/Components/Checks/CheckSiteRegistration.cs
+++ b/Components/Checks/CheckSiteRegistration.cs
@@ -1,5 +1,4 @@
-using System;
-using DotNetNuke.Entities.Portals;
+using DotNetNuke.Entities.Portals;
namespace DNN.Modules.SecurityAnalyzer.Components.Checks
{
@@ -12,25 +11,17 @@ public class CheckSiteRegistration : IAuditCheck
public CheckResult Execute()
{
var result = new CheckResult(SeverityEnum.Unverified, Id);
- try
+ var portalController = new PortalController();
+ result.Severity = SeverityEnum.Pass;
+ foreach (PortalInfo portal in portalController.GetPortals())
{
- var portalController = new PortalController();
- result.Severity = SeverityEnum.Pass;
- foreach (PortalInfo portal in portalController.GetPortals())
+ //check for public registration
+ if (portal.UserRegistration == 2)
{
- //check for public registration
- if (portal.UserRegistration == 2)
- {
- result.Severity = SeverityEnum.Warning;
- result.Notes.Add("Portal:" + portal.PortalName);
- }
+ result.Severity = SeverityEnum.Warning;
+ result.Notes.Add("Portal:" + portal.PortalName);
}
}
- catch (Exception)
- {
- throw;
- }
-
return result;
}
}
diff --git a/Components/Checks/CheckSqlRisk.cs b/Components/Checks/CheckSqlRisk.cs
index 43577df..e989b1b 100644
--- a/Components/Checks/CheckSqlRisk.cs
+++ b/Components/Checks/CheckSqlRisk.cs
@@ -1,7 +1,6 @@
using System.Collections.Generic;
using System.Data.SqlClient;
using System.IO;
-using System.Resources;
using DotNetNuke.Common;
using DotNetNuke.Data;
using DotNetNuke.Services.Localization;
diff --git a/Components/Checks/CheckSuperuserOldPassword.cs b/Components/Checks/CheckSuperuserOldPassword.cs
index bb46e04..fb6f3de 100644
--- a/Components/Checks/CheckSuperuserOldPassword.cs
+++ b/Components/Checks/CheckSuperuserOldPassword.cs
@@ -12,25 +12,17 @@ public class CheckSuperuserOldPassword : IAuditCheck
public CheckResult Execute()
{
var result = new CheckResult(SeverityEnum.Unverified, Id);
- try
+ var totalRecords = 0;
+ var superUsers = UserController.GetUsers(-1, 1, int.MaxValue, ref totalRecords, false, true);
+ result.Severity = SeverityEnum.Pass;
+ foreach (UserInfo user in superUsers)
{
- var totalRecords = 0;
-
- var superUsers = UserController.GetUsers(-1, 1, int.MaxValue, ref totalRecords, false, true);
- result.Severity = SeverityEnum.Pass;
- foreach (UserInfo user in superUsers)
+ if (DateTime.Now.AddMonths(-6) > user.Membership.LastPasswordChangeDate)
{
- if (DateTime.Now.AddMonths(-6) > user.Membership.LastPasswordChangeDate)
- {
- result.Severity = SeverityEnum.Warning;
- result.Notes.Add("Superuser:" + user.Username);
- }
+ result.Severity = SeverityEnum.Warning;
+ result.Notes.Add("Superuser:" + user.Username);
}
}
- catch (Exception)
- {
- throw;
- }
return result;
}
}
diff --git a/Components/FeatureController.cs b/Components/FeatureController.cs
index 198c40c..0744d8d 100644
--- a/Components/FeatureController.cs
+++ b/Components/FeatureController.cs
@@ -8,7 +8,6 @@
using DotNetNuke.Entities.Tabs;
using DotNetNuke.Security;
using DotNetNuke.Security.Permissions;
-using DotNetNuke.Services.Upgrade;
namespace DNN.Modules.SecurityAnalyzer.Components
{
diff --git a/Components/Utility.cs b/Components/Utility.cs
index f167a94..bba0f01 100644
--- a/Components/Utility.cs
+++ b/Components/Utility.cs
@@ -1,6 +1,5 @@
using System;
using System.Collections.Generic;
-using System.Configuration;
using System.Globalization;
using System.IO;
using System.Linq;
diff --git a/ReleaseNotes.txt b/ReleaseNotes.txt
index 825d0e2..0640bd6 100644
--- a/ReleaseNotes.txt
+++ b/ReleaseNotes.txt
@@ -14,7 +14,7 @@