Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Our DNN web site has been hacked!Our DNN web site has been hacked!
Previous
 
Next
New Post
1/2/2008 9:43 AM
 

I am still thinking it is not a 3rd party module, but I was referencing a blog entry by Cathal.  This is not likely your issue (unless this module is installed and not upgraded):

http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryID/422/Default.aspx


Will Strohl

Upendo Ventures Upendo Ventures
DNN experts since 2003
Official provider of the Hotcakes Commerce Cloud and SLA support
 
New Post
1/2/2008 10:17 AM
 

First, any hosting company should provide the raw IIS logs as a matter of service.  But they won't show how you got hacked, because it wasn't an IIS request.  Or DNN.  Or the Onyak modules.  Someone (or something) was able to write to the folders in youir web site.  This is typical of a scripted hack since it was in all folders, and could be due to weak FTP login controls but is more likely the result of a host-wide issue.  Possibly even another hosted account installing a trojan.  Or even you installing one, though if you only run DNN that's less likely.

Your host should be checking all hosted sites, and should be flattening the box and reinstalling with a known-good backup.  If it is only your site, they should be forcing a password change, use of strong passwords and forced rotation of passwords.  You should wipe all your content and reinstall DNN and restore from a known-good backup.

Jeff

 
New Post
1/2/2008 3:38 PM
 

I agree with the comments above.  Also if you have used the DNN password provided by the host I would recommend changing it as you never know who knows that password...


-Mitchel Sellers
Microsoft MVP, ASPInsider, DNN MVP
CEO/Director of Development - IowaComputerGurus Inc.
LinkedIn Profile

Visit mitchelsellers.com for my mostly DNN Blog and support forum.

Visit IowaComputerGurus.com for free DNN Modules, DNN Performance Tips, DNN Consulting Quotes, and DNN Technical Support Services
 
New Post
1/2/2008 4:19 PM
 

From years of experience managing Web servers, and IIS specially, I can tell you that it is not a DNN security weakness.  This is most likely a Web server misconfiguration.  That type of attack has been going on for years by script kiddies that target a bunch of addresses to see which one they can get through.  Believe me, it is not DNN.

This type of attack for instance was done a lot to servers that had the FrontPage Web Server Extensions installed, which are not needed for DNN.  Ask if the FrontPage Web Server extensions are installed on the server you use, if they are, they were probably the culprit, it is tricky to manage the IIS security with the FP Serv Ext installed.  Also, ask them to remove them.

Carlos

 

 
New Post
1/2/2008 4:22 PM
 

FrontPage Server Extensions??!!!  Argh!  I was hoping I would never hear (or read) those words every again in my life.  :(


Will Strohl

Upendo Ventures Upendo Ventures
DNN experts since 2003
Official provider of the Hotcakes Commerce Cloud and SLA support
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Our DNN web site has been hacked!Our DNN web site has been hacked!


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out