Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Security forum; hacking attempt /phplists/admin/index.php?_SERVER[ConfigFile]=../../../../../../../.Security forum; hacking attempt /phplists/admin/index.php?_SERVER[ConfigFile]=../../../../../../../.
Previous
 
Next
New Post
2/27/2011 3:34 PM
 
Bruce Chapman wrote:
In this case, the sender would have received a 500 error as a response code (you can check your logs to confirm).  I would just block that IP.

Thank you,

I would like to block the ip or check where it is originating from. However, I do not find the request in the iis event log, nor it is logged in DNN eventLog....so how to block/ investigate it?

J.

 
New Post
2/27/2011 6:02 PM
 
This is not a DotNetNuke issue - you're event log is simply showing that something tried to access those url's - this is a normal behaviour of scanners such as saint/nessus which use known url's as one of their checks. In general the better tools will identify that a site is .net (or is running windows) but lots of them simply run through their full list of thousands of urls.

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
2/27/2011 7:39 PM
 
Did you check the IIS log? It will be in there, for sure.
 
New Post
2/28/2011 3:05 AM
 
Thank you. I found the event in de IIS log. I did not see it yesterday, but did check it again based on your input. I found the ip number (which I would like to see in the DNN eventlog since not everybody who uses DNN has a dedicated server to look into the IIS logs themselves).

I found next IP and a trace: 86.189.49.42 on 213.121.251.21

Seems a British Telecom user with a fixed line.

tracert 213.121.251.21

Tracing route to 213.121.251.21 over a maximum of 30 hops

...
10 3 ms 3 ms 3 ms te1-3.ccr01.ams05.atlas.cogentco.com [149.6.128.
197]
11 4 ms 3 ms 3 ms te0-3-0-6.ccr21.ams03.atlas.cogentco.com [130.11
7.1.81]
12 10 ms 10 ms 10 ms te0-2-0-1.ccr21.fra03.atlas.cogentco.com [130.11
7.48.166]
13 11 ms 10 ms 10 ms bt.fra03.atlas.cogentco.com [130.117.15.114]
14 11 ms 10 ms 10 ms t2c1-ge13-0-0.de-fra.eu.bt.net [166.49.172.11]
15 21 ms 21 ms 21 ms t2c1-p10-0.uk-glo.eu.bt.net [166.49.195.77]
16 21 ms 21 ms 21 ms t2c1-p9-2.uk-eal.eu.bt.net [166.49.195.202]
17 21 ms 21 ms 21 ms 166-49-168-18.eu.bt.net [166.49.168.18]
18 22 ms 22 ms 21 ms core1-te0-10-0-0.ealing.ukcore.bt.net [62.6.200.
109]
19 26 ms 26 ms 26 ms core1-pos9-0.manchester.ukcore.bt.net [62.6.204.
194]
20 26 ms 27 ms 26 ms vhsaccess1-pos7-0.manchester.fixed.bt.net [62.6.
196.198]
21 29 ms 29 ms 30 ms ftip003178515.vhsaccess1.manchester.fixed-nte.bt
.net [86.189.49.42]
22 33 ms 33 ms 33 ms 213.121.251.21

Trace complete.

I had settings in the host settings doing some regex/ url rewrite. However, after upgrading to DNN 5.6.x those settings are lost.

Added the ip to the custom rewrite rules with a Regex to permanently redirect to www.google.com

(213\.5\.*)|(213\.121\.*)

Now the question is how to report abuse at BT?

J
 
New Post
2/28/2011 3:11 AM
 
@Cathal,

I see that saint/nessus is a vulnerability scanner. I am not using it, so somebody else using it to check my server/ website. If you purchase a hackersafe license of McAfee and set it to an ip or server which is not yours or you do not have permission to. You are seen as a hacker yourself and your subscription ends. I believed you even had to put a file on the server so that the software validates you are the owner of that server.

Does DNN run such tools to check vulnerabilities?

J.
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Security forum; hacking attempt /phplists/admin/index.php?_SERVER[ConfigFile]=../../../../../../../.Security forum; hacking attempt /phplists/admin/index.php?_SERVER[ConfigFile]=../../../../../../../.


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out