Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...DNN 5.6.3 hackedDNN 5.6.3 hacked
Previous
 
Next
New Post
9/14/2011 12:39 PM
 
All of our DNN sites on one of our servers was just hacked today. Many of them were v5.6.3 stable. The Default.aspx was overwritten in each case. Not sure of any more details at this time, trying to restore and clean up the damage. Are there any known vulnerabilities in 5.6.3?
 
New Post
9/14/2011 1:08 PM
 
There is 1 "low" issue which will be resolved in a future 5.6.4 release, but this is very minor and has lots of mitigating factors and has a very low effect (allows access to module settings when the user should only have edit permissions). Please email security@dotnetnuke.com if you have any security related questions. I would recommend you check your IIS logs to determine the issue but when multiple elements are changed it often indicates that it's a server level issue (missing patches/configuration) or a a common factor (e.g. FTP username/password) rather than an issue with individual sites.

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
9/14/2011 5:06 PM
 
Also check for the viruses server wide, recently we had a similar issue with one of our dedicated server client, that turned out to be a virus.

Rashid KAZI
Rashid.KAZI @ DNN4Less.com

Fast & most affordable DotNetNuke Hosting.
Shared Hosting - Resellers Hosting - Cloud Servers - Dedicated Servers

 
New Post
9/15/2011 9:10 AM
 
Wanted to let everyone no this was not a DNN issue. Other non DNN sites were effected as well on that server. Apparently our hosting provider was a day late with some scheduled patches. 
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...DNN 5.6.3 hackedDNN 5.6.3 hacked


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out