Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Hacked DNN Site - version 05.06Hacked DNN Site - version 05.06
Previous
 
Next
New Post
5/10/2011 11:01 PM
 
Has anyone recently been hacked? My site was hacked by "Irtibat: Cyber-Man(at)hotmail.com.tr" and I'm trying to figure out how they did it.  I was running DNN version 05.06.00.  (I'm installing 05.06.02 right now).  My host is also using II6

Any ideas?  There was a cyber.html, he.html and modified Default.aspx (on my root directory).
 
New Post
5/11/2011 3:57 AM
 
check your FTP accounts - weak password are a typical issue, besides make sure to run latest version of DNN and all extensions.

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
5/11/2011 2:13 PM
 
s Sebastian said, FTP could be the way they accessed to your accounts. I recently detected massive connections to my FTP servers trying to break my servers.



My FTP servers are configured to refuse access from an IP if 5 failed logins are detected



However, this will depend on your hosting features to set specific security meassures.



Complex and long passwords are the best options. Also, if your server allows that, then you can enable Secure FTP (SSL or TLS)


Locopon
Free modules: E-commerce, Complete localization (Portal, page, module settings, skins, etc.), Secure Login, and more
http://dnn.tiendaboliviana.com
 
New Post
5/11/2011 2:17 PM
 
Do you have "registrations" turned on for your website? Might look to see if you have that on and then check your permissions on the File Manager for folders under your portal.

You should also check to see if you have allowable file extensions that shouldn't be there on the host settings page.

Chris Hammond
Former DNN Corp Employee, MVP, Core Team Member, Trustee
Christoc.com Software Solutions DotNetNuke Module Development, Upgrades and consulting.
dnnCHAT.com a chat room for DotNetNuke discussions
 
New Post
5/12/2011 6:07 AM
 
Hi,

Once you secured FTP/IIS write access to your DNN files, you may have look at our firewall module to further protect your instance.
The free version includes several security rules:

  • Restrict critical account login to trusted locations (e.g by IP ranges or private aliases)
  • Enforce caps on request rates to prevent Oracle padding or Denial Of Service attacks.
  • Detect multiple connections to prevent identity theft
That helps mitigate the security vulnerabilities from earlier versions.

Regards

Jesse
CTO - Aricie
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Hacked DNN Site - version 05.06Hacked DNN Site - version 05.06


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out