I have a client that found unauthorized, hidden anchortext links inside their site content.
After further research, I found several thousand sites that have this black hat hack with the commonality of being DNN sites.
The inserted scripts vary slightly, yet have the basic format:
Powered by cheap web hosting providers
Designed by XXXX web design services
Ways to make money online click here to try it out
Looking for great deals on cash for gold opportunities, Click here its risk free
I'm curious to know if...
- (a) this is simply a known hole in DotNetNuke security that is being hacked by someone on a mass scale,
- (b) if this hole can be closed - and at what level (site, page, global), and
- (c) if this security hole has been documented anywhere so that I can understand how to explain it to my clients.
Thanks for any input,
Brian
PS. Another script example I found from another such site - as follows:
Powered by cheap web hosting services
speaking of cheap, try this cash for gold opportunities, its great!
* EDIT: Removed links