Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...DNN 7.3.2 HackedDNN 7.3.2 Hacked
Previous
 
Next
New Post
7/10/2015 1:13 PM
 
While I have been using DNN since 4.x, I am not a DNN developer and not knowledgeable about DNN's system and data structure.

Can someone point me to the DNN SQL database table where the hacker likely to inject content to generate the following URL, which redirect user to another site?
http://embedded101.com/nbs.asp?datew3...

Should I search the database to look for entry for: "nbs.asp?datew3vnbfrp-37597.html"

Any help is much appreciated!
Sam
 
New Post
7/10/2015 2:58 PM
 

This tool might be useful.

 http://www.dnnsoftware.com/foru...

 
New Post
7/13/2015 11:06 AM
 
Samuel Phung wrote:
While I have been using DNN since 4.x, I am not a DNN developer and not knowledgeable about DNN's system and data structure.

Can someone point me to the DNN SQL database table where the hacker likely to inject content to generate the following URL, which redirect user to another site?
http://embedded101.com/nbs.asp?datew3...

Should I search the database to look for entry for: "nbs.asp?datew3vnbfrp-37597.html"

Any help is much appreciated!
Sam

 Hello,

first off I wouldn't be worried about the CVE listing - that reflects the list of issues we have resolved and fixed (a number of vulnerability databases such as CVS, securityfocus etc add entries to their database based on http://www.dnnsoftware.com/platform/m... )

Secondly when I look again the problem is not DNN - you have a page called nbs.asp that does the redirect (ie it's a physical page and not a database entry). DNN uses aspx pages, that is a classic asp page. It appears someone has uploaded an asp page to your site -how this was done is difficult to predict. Often asp/php pages are uploaded to sites as part of a server level exploit i.e. a windows IIS server is not correctly patched (or has an old version of a product such as plesk or a mail server that is not patched), and when this is exploited asp/php pages are uploaded to every website on the server. If this is your server I recommend you check other sites, if not please raise it with your host. Note: I highly recommend disabling classic asp if you are not using it.

Note: I recommend you download and install http://www.dnnsoftware.com/forge/dnn-... and use it to check if you have any unexpected host users or poorly configured settings.


Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...DNN 7.3.2 HackedDNN 7.3.2 Hacked


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out