Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Security Issue .. potentially related to Effority or .NET vulnerabilitySecurity Issue .. potentially related to Effority or .NET vulnerability
Previous
 
Next
New Post
1/14/2011 2:22 PM
 
Anyone else seeing issues with links to illegal movie site being embedded within your DNN site outside the normal browser viewable area?  These links are to sites like globalmovies.net, alfamovie.com, ftmovie.com, 100kmovie.com, etc.  It looks like someone has hacked DNN and placed them on legit sites (ones that Google views as legit) for a cross reference boost to their search results within Google.  This would raise these illegal movie sites higher in the search results returned to a typical Google user looking for movies.  These do appear to be scam sites offering illegal copies of Hollywood films or just stealing accounts from users unaware of the site intent.  Anyone aware of this vulnerability and if it is related to a DNN ASP.NET issue or the Effority module database where the content seems to be largely placed?
 
New Post
1/14/2011 7:49 PM
 
Any particular version of DNN that you are seeing this issue with? Sounds like someone got in via a cross site scripting vulnerability or something, that or they got direct access to the database. You can find the previous security bulletins here http://www.dotnetnuke.com/News/SecurityPolicy/tabid/940/Default.aspx

Chris Hammond
Former DNN Corp Employee, MVP, Core Team Member, Trustee
Christoc.com Software Solutions DotNetNuke Module Development, Upgrades and consulting.
dnnCHAT.com a chat room for DotNetNuke discussions
 
New Post
1/18/2011 10:29 AM
 
DNN 04.09.04 though the attack appears limited to just the 'Text/HTML with Workflow' data table of which we are running Effority.net's 00.05.01 version.
 
New Post
1/20/2011 11:23 AM
 
Ideas anyone?  Anyone have release notes for Effority 00.07.03?  Know if this is a known issue with the Text/HTML with Workflow module?
 
New Post
1/20/2011 12:10 PM
 
I don't see any listing of the issue in their issuetracker - http://workflow.codeplex.com/workitem/list/basic , perhaps you could log one with more details then they can look to resolve it (very good work determining the issue BTW)

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Security Issue .. potentially related to Effority or .NET vulnerabilitySecurity Issue .. potentially related to Effority or .NET vulnerability


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out