Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Possible SQL injection problemPossible SQL injection problem
Previous
 
Next
New Post
5/14/2008 8:52 PM
 

I'm having some problems with my  site today.  My site is uses Dotnetnuke version 4.8.2,  Currently I have both non-dnn pages and dnn page. Nothing is being displayed on the homepage and I receive a "The hostname could not be parsed" when I visit it..  I can get to other dnn pages using the tabid instead but not the friendly name that was working yesterday, once I visit one the other pages and click on any link I'm redirected to another site. When you view the source of the page  the link looks like this; <menuitem id="69" title="&amp;nbsp;On The Road" url="catadjuster.org&lt;script src=http://www.bad site link.com/b.js&gt;&lt;/script&gt;/Home/OnTheRoad.aspx" />.  Also, when I try to login I receive a "invalid character in a Base-64 string" error. 

I currently have the site offline but did not have any trouble with the site yesterday and I do not have any trouble with the links on the non-dnn pages work good.  I restored a backup of the MSSQL database hoping this would clear things up but it did not.  I believe there may have been some SQL injection attempt on the non-dnn pages but I'm not sure.  Any thoughts on where to look fo the problems? 

 
New Post
5/15/2008 1:24 AM
 

Roy,

What kind of non DNN pages do you have running on your site? Any forms access the DNN database?


Chris Hammond
Former DNN Corp Employee, MVP, Core Team Member, Trustee
Christoc.com Software Solutions DotNetNuke Module Development, Upgrades and consulting.
dnnCHAT.com a chat room for DotNetNuke discussions
 
New Post
5/15/2008 7:52 AM
 

Hi Chris,

 

Yes I use many forms on the DNN pages.  When checking the database so far I have found the script that redirects links to a site that trys to download additional scripts in the text fields of DesktopModules and ActiveForms_MC tables.

 
New Post
5/15/2008 8:34 AM
 

I'm sorry I stated DNN pages but I do have forms on the non-DNN as well.

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Possible SQL injection problemPossible SQL injection problem


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out