Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Our DNN web site has been hacked!Our DNN web site has been hacked!
Previous
 
Next
New Post
1/5/2008 7:20 AM
 

Hi again everyone.

Tanks people for good input and feedback. The host still calims that this is DNN, and as someone said that I would not find anything in the IIS log. That was true. We did find out that there was a virus in the directory structure, I can't remember what it was but it said something about "backdoor". This was defenitely a scripting job, and I also think that (God forbid..) Front Page Extension is installed on the server. I have an option to install it for our web site by changing an option through my customer service account.

The host is a web hosting company in Norway, and I think I'll keep it as a secret for now. There were other DNN sites on the host that also were attacked, so we were not the only one. I am suspecting that some smuck installed something for another account, and then something happened. I have been running DNN for another website on that host for almost 2 years without anything happening.

Again; thank you everyone for valuable feedback.

Ronny

 
New Post
1/5/2008 1:15 PM
 

Also make sure that no one has the ftp information and you aren't e-mailing ftp information.  I have seen people who e-mail ftp info end up getting their directories hacked and next thing you know your root is filled with all sorts of new default documents.  Some of the most common malicious code is e-mail related, so I would refrain from sending that info over e-mail.  I know a lot of ad companies had to change their policies because so many people had ftp information to various sites to upload ads, many of those sites were compromised at one time or another.  Just my two sense.

 
New Post
1/6/2008 6:14 PM
 

mn96.dns.gendistr.info: my users get a redirect to the above which downloads a virus. Does anyone know how this is possible? Each time my site gets corrupted i install a clean versdion which works for a while then the problem re-appears. Can anyone please help? The hosting company blames a hole in DNN.

 
New Post
1/7/2008 3:49 AM
 

Please contact Cathal at security@dotnetnuke.com.


Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
1/8/2008 11:48 AM
 

bhinesh wrote

mn96.dns.gendistr.info: my users get a redirect to the above which downloads a virus. Does anyone know how this is possible? Each time my site gets corrupted i install a clean versdion which works for a while then the problem re-appears. Can anyone please help? The hosting company blames a hole in DNN.

Most likely, as with the original poster, your hosting company has something open and people are getting in and putting in a new default file into the root of your website which is redirecting your users before default.aspx gets hit


Chris Hammond
Former DNN Corp Employee, MVP, Core Team Member, Trustee
Christoc.com Software Solutions DotNetNuke Module Development, Upgrades and consulting.
dnnCHAT.com a chat room for DotNetNuke discussions
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Our DNN web site has been hacked!Our DNN web site has been hacked!


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out