Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Beware! DNN website being compromised! "starvingarctic.ru"Beware! DNN website being compromised! "starvingarctic.ru"
Previous
 
Next
New Post
8/10/2010 11:18 PM
 
Just awhile ago, one of my old DNN website ( version 5.3.0 ) was loaded with the following script:

Please do not visit:


You can use Firebug to easily identify if your website is loading suspicious scripts and links.
The script can be found in all .js files under /js directory.

This script usually targeting SMF sites but now it is targeting DNN website as well.

Personally I don't think it is DotNetNuke security issue but FTP issue.

Lastly, please upgrade to latest DNN version and change FTP password regularly.

Thanks,
George

Where to eat? Visit GoEatOut for Food Promotion in Kuala Lumpur.
 
New Post
8/11/2010 1:23 PM
 
thank you for publicising this. I agree with your assessment in that we strip dangerous text such as javascript (caveat: this may come from a 3rd party module). We are seeing more cases of this type of thing happening via sql injection (often a legacy application on the same server as DotNetNuke core & core modules do not suffer from sql injection), virus based changes (one example was a virus that keylogged a users ftp details and then silently logged in and made the changes), and cracked ftp passwords.

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Beware! DNN website being compromised! "starvingarctic.ru"Beware! DNN website being compromised! "starvingarctic.ru"


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out