Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Bad Links Showing Up In CodeBad Links Showing Up In Code
Previous
 
Next
New Post
12/25/2010 1:40 AM
 
Hi All,

One of our customers reported a very interesting issue a couple of days ago.  Somehow at the bottom of all of their pages there are several unauthorized links to porn sites. Now none of the links are clickable but  you can certainly see them when you view the source code and scroll down. At first we thought maybe a module allowed this through some sort of SQL injection but this is on each and every page which seems kinda weird. Plus it's outside of the HTML tags so that's a little weird too. The other issue is that, because they are hosting this and we cannot replicate how it could have happen, we are unsure how to 1) remove the data and 2) how to stop it from happening in the future.  We haven't gone the route of having them back everything up and send it to us yet cause I wanted to get the pulse of the community before we turned this into a major project.

The URL is http://www.dataio.com. Any input from the community would be greatly appreciated.

DNN Community Edition 5.2.2


Thanks and happy holidays!
 
New Post
12/25/2010 2:26 AM
 
I would check the default.aspx file and see if the date stamp has changed at all, or compare to a backed up version. I know there were issues with .net 2.0 framework code injection particularly affecting Windows 2k3 & IIS6 machines but that was back in September and there was a fix for it as well as a recommended upgrade, however, it allowed replacement of default files, rather than adding to the existing default.aspx file. I would also look at the Portals/0 folder and see if there are any recent odd files that have been added. You could also email security@dotnetnuke.com and see if they have had any similar issues. Merry Christmas to you too in spite of having to find something like this to handle when you should be relaxing with family or eating some delicious Christmas food. Nina Meiers

Nina Meiers My Little Website
If it's on DNN, I fix, build, deploy, support,skin, host, design, consult, implement, integrate and done since 2003.
Who am I? Just a city chic, having a crack at organic berry farming.. and creating awesome websites.
 
New Post
12/25/2010 2:49 AM
 
Thanks Nina,



I will check out some of those things, not sure if they did do the .NET upgrade from a few months ago (I remember that caused a few problems even on the DNN site). Luckily I'll only have to work on this after the holiday's. Thanks for the quick suggestions, happy holidays to you and yours.
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Bad Links Showing Up In CodeBad Links Showing Up In Code


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out