Hi everyone.
This holiday our hosted web site has been hacked. Or... is it the hosting environment that has been hacked...?
What happenened was that someone has been able to copy a lot of different default index files with different extensions, 10 files in total. Whn someone tried to look at the site, one of the default files came up telling that the site was hacked by, and then 3 names. The files was copied into all the directories in the site, the root included.
Now, is this a security hoel in DNN? If so how can that be? The host user for DNN is using the username and pwd provided by the hosting company. The hosting company tells me that this is a problem with DNN and a problem with open source. I am not sure that I want to accept that as it is.
Can someone tell me what security actions I have to take when I am hosting my site somewhere. We are not running any modules other that the ones that we can download at DotNetNuke.com and that are "included". We are running on DNN 4.7.
I know that the hosting company installed a security update from Microsoft some weeks ago, and all the DNN sites was not working after that because the .net version was reset to version 1.1. We are running on .net 2.0. Could this have someting to do with what happened? I am not sure how to approach this with the hosting company since they claim that this is DNN's fault. But what can I expect? That they would say: "Yes, we're the ones to blaim because we have not our routines in place?"
So if anyone have any idea what have happend, why it could happen, and if I can protect the site against it or not, or if it is the hostin company's responibility, I am happy to receive feedback in any shape or form.
Uppen