Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Hacked! Hacked!
Previous
 
Next
New Post
11/22/2010 2:09 PM
 
public users do not need write permission at all, upload of files is done via ASP.Net (and associated user account). Please make sure the windows account used by ASP.Net (as configured in your IIS application pool) does have full create/write/edit/delete permissions for files and folders.

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
11/23/2010 9:25 AM
 
Hi Sebastian,
Thanks for your input. Public users I believe don;t have write permision. I was talking about what my hosting company calls the IUSER account which is I assume the ASP .NET worker process.
Are you saying that this account should have full read/write access to the entire dot net nuke folder (ie for performing upgrades etc). Is this therefore a 'secure' configuration to run with .... and still leads me to ask how a hacker could use this process to srite a file - presuambly through a security flaw in DNN somewhere ?

Thanks
Rob
 
New Post
11/23/2010 11:58 AM
 
since the ASP.Net account can only be used by DNN itself, it is save to grant full permissions - if a hacker runs the asp.net access, there is not much harm if he is able to affect core files as well. Full permissions are needed to install modules, language packs, providers etc.

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
11/24/2010 4:16 AM
 
rob nisbet wrote:
Hi Sebastian,
Thanks for your input. Public users I believe don;t have write permision. I was talking about what my hosting company calls the IUSER account which is I assume the ASP .NET worker process. 

Yo Rob - NO NO NO :)  The NETWORK SERVICE (Server 2003) or ASP.NET service (2008) does NOT equal the IIUSER account.  The former listed service accounts (depending on the Server version running) are the only required accounts that need full permissions.  The IUSER account should not be needed at all!

However, it maybe, due to the setup at your host (I'd be interested in hearing more on how they've done it) *may* require the IUSER account to have READ privilege.  That's all it will need.

Cheers,  Duncan.
 
New Post
11/24/2010 8:12 AM
 
Well if it is a shared web hosting, it might be the infected files are generated from other website that has already been hacked, most hackers place a file script into a site folder, by viewing the file and running it through web, it can generate files that will copy and replaced existing files. Mostly what hackers done is replacing the default page like index.html, default.htm, etc. Based on my experience they do it in purpose to tell you that your site is vulnerable so 60% are not harmful. Most of them posted trick and tips in hacker forums and teach newbie on how to hack the sites that they have done
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Hacked! Hacked!


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out