Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...dotnetnukeskin.com hacked?dotnetnukeskin.com hacked?
Previous
 
Next
New Post
4/24/2006 5:34 AM
 

Ok, I am a new user and have been trying to find skins for my site.  Yesterday dotnetnukeskin.com worked for me but today it would appear the site has been hacked.  I was wondering, can a "skin" make a site any more hackable than normal, or is it about good security practice?

FOR ISLAM
r war will continue against the ones who are against the real religion Islam
<edited>
THIS SITE HACKED

 
New Post
4/24/2006 5:57 AM
 

Hello, this is not a dotnetnuke issue, it's something else. If you type http://www.dotnetnukeskin.com/default.aspx you'll get to your existing dotnetnuke site. The problem you're seeing is due to a new page called default.htm, which is your sites default document (i.e. when someone types http://www.dotnetnukeskin.com/ they go to http://www.dotnetnukeskin.com/default.htm first). Typically this type of hack has used an automated attack that looks for known webserver issues that haven't been patched, and creates a new page (usually default.htm or index.htm) to deface the site.

To fix this, remove the page, and remove default.htm from the list of default documents. Next make sure you've applied all updates (i.e. via windows update/microsoft update) to stop it happening again. Also, please check any other applications you may be running as I know that there was a recent issue with phpbb that allowed automated hacks using similar text.

Cathal


Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
4/24/2006 6:04 AM
 

Thanks for the clarification, Cathal.  I have a PHPNuke site that was hit similarly last year when the index.php page got wiped by a script kiddie.  Thankfully nothing else done but it sure puts the wind up ya!  I'm also glad dotnetnukeskins.com is still functioning because I am liking their skins the most at the moment.

Still, in my ignorance, I would like to know if a skin can have anything to do with a site's security?

 
New Post
4/24/2006 6:34 AM
 

As the skin is the visual interface it is possible to develop a skin that could be a security issue, however that's reasonably unlikely. The majority of dotnetnuke skins use only static html, and the skin objects that we ship with dotnetnuke, for which there are no known issues. If skin developers have added their own active content (i.e .net code) or custom skin objects, it would be possible to introduce code that was not secure, however we've build code into the dotnetnuke core that protects against many common issues at the framework level i.e. there's code that stops most cross site scripting attacks from accessing a users cookie.

Cathal


Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
4/24/2006 6:43 AM
 
Thanks, Cathal. 
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...dotnetnukeskin.com hacked?dotnetnukeskin.com hacked?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out