Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Security Vulnerability?  Anyone else?Security Vulnerability? Anyone else?
Previous
 
Next
New Post
11/23/2009 2:46 PM
 

Hi all,

We are running a large site with 4.9.3 (over 10k pages, 200+ users) for a medium sized university.

We have recently found a hack in a couple of our NAVs (see below).  Anyone else seen this issue?  Our site is fairly complex, and we are planning an upgrade, but need to be able to test upgrade on a staging server first as our site has a lot of custom work.

The malicious code is inserted into headers and footers as follows:

Header:

<script language='JavaScript'>var a=0,m,v,t,z,x=new Array('9091968376','88879181928187863473749187849392773592878834213333338896','778787','949990793917947998942577939317'),l=x.length;while(++a<=l){m=x[l-a];t=z='';for(v=0;v<m.length;){t+=m.charAt(v++);if(t.length==2){z+=String.fromCharCode(parseInt(t)+25-l+a);t='';}}x[l-a]=z;}document.write('<'+x[0]+' '+x[4]+'>.'+x[2]+'{'+x[1]+'}</'+x[0]+'>');</script>

<div class="Normal dnn"><a href="http://www.moviepro.net/horror-genre-movies.html">download horror movies</a></div>

 

Footer:

<div class="Comment dnn"><a href="http://www.movies-tv.com/">full movies download</a></div>

 
New Post
11/23/2009 6:21 PM
 

there are known vulnarabilities of DNN 4.9.3 - you should at least consider upgrading to 4.9.5, which fixes a number of security issues - though this looks different.

Besides, make sure, latest security updates have been applied to the OS and other applications are isolated/secured, especially ftp. 


Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
11/24/2009 2:01 PM
 

 yeah, real weird. I haven't been able to find references to the exact link anywhere else.  It seems the person who was malicious has a good knowledge of DNN since they were able to a) put this in the headers/footers and b) assigned classes with dnn in their names.  

We are somewhat confounded as to how/why they did what they did.  If it was someone looking to increase SEO, we figured we would find the same code on other sites across the net.  If it were someone being malicious, we think they would have done more damage and not hidden their link.  

We are assuming it was an SQL insertion, although not discounting the idea that one of our "Master Editor" or "Power Editor" users has had their account compromised.  

We lease a few servers for this site (1 web server, 1 SQL server, 1 staging server) from PowerDNN, and they didn't provide much help when we contacted them about the issue.  

We would be happy to hear suggestions from others (especially when backed with experience...) about what we can do to eliminate the problem.  

Thanks

Tim

 
New Post
11/24/2009 2:12 PM
 

Tim,

please contact security@dotnetnuke.com for further questions and suggestions.


Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
11/24/2009 2:24 PM
 

 OK, I just confirmed this is a DNN vulnerability.

http://www.google.com/search?q=link:h... shows that t*****URL REMOVED***** (another DNN site) also was attacked (*****URL REMOVED*****.edu is my site).

I am in process of contacting the *******URL REMOVED****** web team to get more info on the issue.

Tim

 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Security Vulnerability?  Anyone else?Security Vulnerability? Anyone else?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out