Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Apparent Host | Site Management BreachApparent Host | Site Management Breach
Previous
 
Next
New Post
7/13/2014 3:17 PM
 
Suspicious_Portal0_Aliases.xlsx

In setting up a new site which will have SSL even though it will be using pay pal as its payment provider, the portal alias table was checked in order to set up the registered domain name.  This was done prior to copying over the database.  6 portal 0 aliases were found in the Portal Alias table with the user ID of -1, or host.

I've attached the Excel file I made by copying the table contents.  I got with the provider and found that when changing server boxes the IP lockdown for RDP wasn't duplicated and also the FTP lockdown wasn't as well.  Those have now been set and it is verified that only one IP can RDP in and only specific FTP accounts set up with dedicated IPs can log in.  Also, of course, Host and Admin passwords were changed.

My concern is to cover all bases.  There is no way in now via RDP or FTP but what about through any other client side code such as javascript, etc.?

The Excel file is attached showing the fake aliases that were set up.  This may be useful info for anyone who tracks down such intrusion attempts as part of their work.  Is there such an investigative agency to send this info to?

Thanks,

Mike

 
New Post
7/13/2014 3:53 PM
 
you need to uncheck "auto add portal alias" in Site Settings.
I' provide two bindings for the website, one using http and website host header and the other using the SSL IP address with host header and SSL port.
Next enable SSL and check access working properly, before you require SSL for all pages in question.

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
7/13/2014 4:57 PM
 

Thanks for the very quick answer, much appreciated.

It's not germane to the post but the file I tried to upload doesn't seem to open.  The link is right at the top of the post.

For future reference, what does it take to get a file attached?  Mine did go into a folder and I saw it display in the folder.  But ... it won't open at all when it is clicked.

Thanks,

Mike

 
New Post
7/13/2014 6:34 PM
 
I was able to open the file (there seem to be an issue with the link tool, but that's not the biggest issue around).
Have you been able to adjust your aliases and SSL settings?

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
7/13/2014 7:55 PM
 

First of all, being German by family, CHEERS for winning the World Cup.  I loved it, though I was here coding and didn't get to watch.  I just read the article on Bing Sports.

Nope, haven't set SSL in yet.  One thing at a time.  I just set up the name servers for the registered domain, edited Portal Alias, etc.  I'll wait for this to propagate first and then make sure all is normal.

Next will be to get the certificate ordered and applied, that working, then enforce/enable SSL and set up pages.

Thanks much for pointing out disabling the auto-create aliases.  If that can be so easily leveraged by a hacker I would think it would be disabled by default?  It's new functionality to me ... what is its advantage over just manually setting up aliases for portal 0?

 Cheers,

Mike

 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Apparent Host | Site Management BreachApparent Host | Site Management Breach


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out