Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Plugging a Security Hole in DNNPlugging a Security Hole in DNN
Previous
 
Next
New Post
7/6/2010 4:00 AM
 
I have a client that found unauthorized, hidden anchortext links inside their site content.

After further research, I found several thousand sites that have this black hat hack with the commonality of being DNN sites.

The inserted scripts vary slightly, yet have the basic format:

Powered by cheap web hosting providers

Designed by XXXX web design services

Ways to make money online click here to try it out

Looking for great deals on cash for gold opportunities, Click here its risk free

I'm curious to know if...

  • (a) this is simply a known hole in DotNetNuke security that is being hacked by someone on a mass scale,
  • (b) if this hole can be closed - and at what level (site, page, global), and
  • (c) if this security hole has been documented anywhere so that I can understand how to explain it to my clients.

Thanks for any input,
Brian


PS.  Another script example I found from another such site - as follows:

Powered by cheap web hosting services


speaking of cheap, try this cash for gold opportunities, its great!

* EDIT: Removed links

 
New Post
7/6/2010 4:39 AM
 
Brian, which core version of the framework are you using? Also, which module is the one they have hijacked (I assume HTML module)? I am pretty sure this issue has been resolved for a long time, even your post here wouldn't allow part of what you originally posted during the submission process (which uses the core security filters). You can view security notes on the Security Policy page here

Chris Paterra

Get direct answers to your questions in the Community Exchange.
 
New Post
7/6/2010 4:46 AM
 
Thanks for your response.

As I am management (haven't been a developer for years, and am not the developer for any of these sites), the version used by each site is unknown to me.

I was made aware of it by a client who wanted assistance.  The pattern I recognized was a series of hidden links that have been published in such high volume to DNN-developed sites that it appears to be a security hole in older versions perhaps that haven't been patched yet.
 
New Post
7/6/2010 5:02 AM
 
I understand where you are coming from, I would work with your developer on this issues (see what version of the core is installed, any host can see this logged in). Then read the security notes to see if an upgrade is necessary.  

As for the links, I removed these and ask that you please don't post any information that would link to these sites (even if they are not direct link in the post). The last thing we want to do is promote this more. 

Chris Paterra

Get direct answers to your questions in the Community Exchange.
 
New Post
7/6/2010 5:05 AM
 
Understood. As none of these are my sites, I'll advise my client to get the DNN code corrected. As far as the black hat SEO abuse, I'll report the code pattern to Google and let them de-list sites as they see fit according to their terms of service. Thanks for your input, Brian
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Plugging a Security Hole in DNNPlugging a Security Hole in DNN


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out