Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityCommunity Membe...Community Membe...Simple security check for your siteSimple security check for your site
Previous
 
Next
New Post
9/12/2011 9:35 AM
 
I found a vulnerability in two of my DNN sites (5.6.3) that hackers were exploiting to upload shell files into the root. To see if your site has the vulnerability the hackers are finding try this from Google:

site:www.yoursite.com upload -intellectual

(-intellectual gets rid of results for your 'Terms' pages)

Check through those pages that return the word upload to make sure there is not a vulnerability on your site with a page that allows anonymous uploads into the file structure.

thanks,

Will Sugg, Planet Maine
 
New Post
9/12/2011 1:37 PM
 
Please note, there is no known vulnerability with DotNetNuke 5.6.3 regarding uploads. The advice Will is giving is valid in that some 3rd party modules may have added aspx pages to handle uploads and these pages if found may allow a hacker the ability to upload a file. Searching for potential issues such as this is known as "google dorking" and is a common technique to search for known or potential problems - and it makes sense for users to apply the same techniques to ensure that any 3rd party modules do not contain potential vulnerable pages such as this.

As to the upload of shell files -this relies on the site running on IIS6 (which is no longer a supported OS) and not applying a secure configuration and is not a DotNetNuke issue - i blogged on this a few years back at http://www.dotnetnuke.com/Resources/B... . Please note, we added code in 6.0 to check for the semicolon asp bug issue to provide protection for sites still running under IIS6 - upgrading to that version will stop the shell attacks.


Thanks.

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
9/12/2011 5:27 PM
 
Right - not implying at all a security issue with 5.6.3 rather this searches for third party modules that have the weakness. That was our issue. - thanks
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityCommunity Membe...Community Membe...Simple security check for your siteSimple security check for your site


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out