Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Security Issue MANY are havingSecurity Issue MANY are having
Previous
 
Next
New Post
7/7/2009 4:37 PM
 

Something happened today that really pissed me off.

First of all, I was on the FTP uploading some new images to my portals/0 folder when I noticed a .txt file that had a silly name.

I downloaded it, virus scanned it and opened it to find a little spiel about Turkish Hackers and some other nonsense. Now I know this sort of thing is stupid and harmless but it really worried me that a more advanced hacker could exploit this even more.

I searched the term "Federal Atack Team" on google because I found 4 files in my portal/0 that had this labeling somewhere in the text... the next thing I know I have hundreds of results on google with the same .txt files and most of them were in company's website's portal/0 folders.

Now I'm not a security expert but I would assume these "hackers" found an exploit in a registration form or something of that sort and were able to SQL inject it with a .txt file.

 

Please get back to me with an explaination and a patch! And please google the above phrase and see that this effects almost everyone who uses DNN.

 

Thanks.

 
New Post
7/7/2009 6:38 PM
 

This was a security hole found over a year ago. It was corrected in 4.8.3 and 4.8.4, I recommend upgrading to 4.9.4 IMMEDIATELY to fix all known security holes.


Chris Hammond
Former DNN Corp Employee, MVP, Core Team Member, Trustee
Christoc.com Software Solutions DotNetNuke Module Development, Upgrades and consulting.
dnnCHAT.com a chat room for DotNetNuke discussions
 
New Post
7/8/2009 8:57 AM
 

on top of the info Chris provided: please sure to review the DNN security policy and bulletins, located here: http://www.dotnetnuke.com/tabid/1246/Default.aspx


Erik van Ballegoij, Former DNN Corp. Employee and DNN Expert

DNN Blog | Twitter: @erikvb | LinkedIn: Erik van Ballegoij on LinkedIn

 
New Post
7/8/2009 9:31 AM
 

Old news.....



Alex Shirley


 
New Post
7/9/2009 3:11 AM
 

Alex Shirley wrote
 

Old news.....

this just goes to show that there are many site owners that are running old dnn versions without knowing the risks. I guess thats not something we can solve, other than having some kind of auto update functionality. Prior to when microsoft came up with windows update, people didnt apply security patches either...


Erik van Ballegoij, Former DNN Corp. Employee and DNN Expert

DNN Blog | Twitter: @erikvb | LinkedIn: Erik van Ballegoij on LinkedIn

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Security Issue MANY are havingSecurity Issue MANY are having


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out