Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...DNN site defaced - URGENT SECURITY QUESTION !!!!!!!!DNN site defaced - URGENT SECURITY QUESTION !!!!!!!!
Previous
 
Next
New Post
3/29/2010 3:54 PM
 

I didn't submit this to the bug tracker because I believe that I'm missing a configuration or setup on the folder security that fixes this problem.

One of my customers has had his dnn site (with over 200,000 registered users) defaced SEVERAL TIMES in the last 2 weeks. I was able to easily replicate the security issues and upload asp files to any of the dnn websites I have running for other customers, including dnn 5.x. This is ONLY IF they are installed on IIS6.

It seems to be a problem of IIS6, and if you add another problem with FCK gallery, then you are able to upload and execute any asp file.

Here's the information of the IIS6 vulnerability: http://soroush.secproject.com/downloadable/iis-semicolon-report.pdf
Here's the information of the FCK Gallery vulnerability: http://securityreason.com/exploitalert/6234

Here's how you can duplicate the vulnerability on any of your dnn websites running on IIS6:

- Navigate to your dnn installation here: /Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx
- If it doesn't let you upload a document, then register as a normal user and go back to the same url. You should see the option to upload a file now.
- Rename any asp file on your computer to something like this:  yourfilename.asp;123456.jpg
- Upload the file to a folder. The asp file will be accepted like if it was a jpg.
- Go to the url and run the asp file  (like /Portals/0/yourfilename.asp;123456.jpg    It will run the asp.

There must be a way to fix this configuring the security of the folders in Windows, but I haven't been able to figure it out.

Does anybody know how to fix it?

 
New Post
3/29/2010 4:07 PM
 

please read here


Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
3/29/2010 4:25 PM
 
if you encounter issues with later versions of the framework, please contact security@dotnetnuke.com privately. Thank you.

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
3/29/2010 7:20 PM
 

Thank you so much Leopold, Those are production servers and I can't upgrade them to IIS7 but editing the portals folder in IIS and deleting the scripts from the permissions did the trick. I can't believe I didn't think about that.

Sorry about the panicking of my last post.

 
New Post
3/29/2010 9:01 PM
 
glad you were able to solve your issue :)

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...DNN site defaced - URGENT SECURITY QUESTION !!!!!!!!DNN site defaced - URGENT SECURITY QUESTION !!!!!!!!


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out