Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...My DotNetNuke is being Hacked My DotNetNuke is being Hacked
Previous
 
Next
New Post
6/23/2009 8:57 AM
 

Hi,

  I really cannot find the injected file in the file system. If i would like to re-configure a new DNN, and i would like to maintain those information, what i should back up so that i can reuse it ?

 

 

 
New Post
6/23/2009 9:10 PM
 

if it is a virtual file, generated by a modified code file, you won't gain anything and starting from the scratch, you will loose all existing data. Try to solve the issue instead of circumvent it :))


Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
6/16/2010 9:47 PM
 
I don't know if this helps but this gave me a world of headaches (and a 200 hour work week). Here is what I finally figured out. All of the previous posts are true, and when someone says "just upgrade to the current version of DNN" sometimes it's not that simple. Anyone working with third party modules knows the craziness upgrading can bring. Also, if you have multiple site, it's hard to tell where the file is. Here is how you find it. This flaw has to do with a flaw in DNN, IIS 6.0 and having execute permissions. While it's easy for someone to sit back and say, well you shouldn't have execute permissions, while that is also true, sometimes you have to for other reasons. People need to understand every case is unique. Ok I'm done ranting, as for the fix...the main flaw that this has is an issue with iis running any script passed in a url with a ; i.e. let's say you create an asp file but name it thisFileRuns.asp;.jpg that files shows as a jpg. However if you put <img src="thisFileRuns.asp;.jpg /> in your html, that file runs. The only fix I found is to look through all of your websites and see if you can find any files that have a ; in the name.  Unless your in the habit of putting ;'s in your file names, One you find and delete all of those files, you can restore your directories or start rebuilding your site. While we did a full restore, the issue I found is that this file had been on the server for months before it actually ran. I have not found this fix anywhere on the internet and am posting it wherever I find forums about this. I'm hoping to save someone migrating to a new server and moving 130+ sites as I had to, and THEN finding the problem. Some people might say it's a simple fix, but hindsight is always 20/20, and as I mentioned we had 130+ sites, That's like trying to find a needle in a stack of needles.

 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...My DotNetNuke is being Hacked My DotNetNuke is being Hacked


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out