Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Can I change this?Can I change this?
Previous
 
Next
New Post
2/1/2008 3:45 AM
 

Hi.

I host my site on a dedicated server running MS Server 2003 SP2 fully patched (and checked daily) and yet on a couple of occasions I have had the home page "taken over" by hackers who drop in replacement default home pages. I have run MS BSA 2.1 and everything seems right.

The first time they did this they only dropped in "Index.html" and because I hadn't deleted the defaults in IIS that was served before "Default.aspx" so all I did was to delete .html and in IIS documents remove everything except "Default.aspx". Second time they dropped in a new "Default.aspx" which threw me for a while as I thought the whole site was compromised but then I realised it was simply another html file that redirected to their site.

Googling the names from one of the pages source, I see that hundreds of servers are similarly disrupted including ones running PHP NUke therefore I dont think they are coming in via DNN. I have changed passwords etc. in case they have a login, but I think there is something in the server I haven't locked down yet - though I cant see what its. So as a further defensive measure, I thought I would try changing the name of Default.aspx to something very different and adding that to IIS and see if that slows down the next attack (which will no doubt surely come).

My question is: Can I do that without breaking DNN? and if so what do I need to do?

Thoughts or advice would be much appreciated.

Cheers

Julian

 
New Post
2/1/2008 12:27 PM
 

Fix your security hole instead.  FTP login/password, have FrontPage extensions, WebDAV enabled, etc. will give access to deposit a file on the system without needing access through DNN.

Jeff

 
New Post
2/2/2008 3:59 AM
 

Jeff, thanks and yes you are right but . . .

FTP login/password - FTP is disabled I am using RDC
FrontPage extensions - Disabled
WebDAV - Disabled
Users on the Server? - Me Only
Always used strong passwords.
every other un-needed service etc is disabled. 
All the above have been since day one! :-(

All my passwords have been changed - there are several sites on the server and this particular one is the only that gets hit - at least it was targeted the second time maybe because it has a "military" connection - though nothing relevant to today's troubles!

With the files hosted on D: drive not in the default IIS folders I am suspicous of the means of entry - though I do not believe it is through DNN - I thought I made that clear :-)

I have disabled everything I can think of, its checked and patched daily in case W Update misses something - and still there is a way in. 

I agree I need to find out how this is happening and I am taking measures to do so but in the mean time is there a way to change the name of the default page please????

 

 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Can I change this?Can I change this?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out