Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Security breachSecurity breach
Previous
 
Next
New Post
1/6/2011 2:56 PM
 
There is a backdoor security problem with DNN. Twice in a three year period, someone has been able to log onto our system and make random changes.

How can I stop this from happening in the future?

Is there a log of who and when people log onto DNN sites?
 
New Post
1/6/2011 3:10 PM
 
You can find the security bulletins on the Security Center page, as well as a number of fixes for those with new releases of DNN

http://www.dotnetnuke.com/News/Securi...

There have been a number of issues over the past couple of years.

You can see a history of logins in the Event Log/Event Viewer under the Admin menu. 


What version of DNN are you on?

Chris Hammond
Former DNN Corp Employee, MVP, Core Team Member, Trustee
Christoc.com Software Solutions DotNetNuke Module Development, Upgrades and consulting.
dnnCHAT.com a chat room for DotNetNuke discussions
 
New Post
1/6/2011 5:23 PM
 
version 5 or better, not able to confirm right now it.
 
New Post
1/6/2011 5:31 PM
 
It is version 5.1.4
 
New Post
1/6/2011 6:50 PM
 
I'm not a security guy, but I don't recall any major user exploit issues specific to DNN within the past year. That being said. If you haven't run Windows Updates on your server since September you are likely vulnerable to the ASP.NET security vulnerability and that would leave DNN open to being compromised. Another thing to do would be to make sure you aren't using default passwords for the Admin or Host accounts, and review all users on the site to see if anyone has promoted themselves into either the Administrators role or made themselves a SuperUser.

Chris Hammond
Former DNN Corp Employee, MVP, Core Team Member, Trustee
Christoc.com Software Solutions DotNetNuke Module Development, Upgrades and consulting.
dnnCHAT.com a chat room for DotNetNuke discussions
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Security breachSecurity breach


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out