Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...DNN 6.2 and DNN 7.2 Hacked already... HELP ME....DNN 6.2 and DNN 7.2 Hacked already... HELP ME....
Previous
 
Next
New Post
6/18/2014 6:01 PM
 

Please help me, I make two website for two client by DNN one for www.kindcare.ae it’s clinic in Dubai and one www.yaghoubi.ae is advertising company both are hacked I think because dayly I receive 200 Registered User and send several notification emails and I check registered it was automatic generated by real database and some of them contact us that they never register and why you register us? We don’t register them and some automatic generator come and hacked DNN and register 2000 people in 5 days…..!!!!

I add CAPCHA, maybe reflect to control this attach but not effected and now I Close my Register from site setting NONE radio button on registering item….. I hope be answer to stop it.

 

Please help me how can finish it and how can remove these users? Its about 4000 now…. HELP PLEASE……

 

 
New Post
6/18/2014 6:26 PM
 
Armin,
this is a known issue - not really a hack, see http://www.dnnsoftware.com/community-...
Interactive webs seems to have a nice module to solve it (sorry, haven't been able to test it yet).

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
6/18/2014 6:30 PM
 
Hi Armin,

Every DNN site appears to be suffering from this bot madness to greater and lesser degrees. It sounds like you're really getting hit hard.

There are some things to look at...

1) Make sure your Site is set to only allow Verified registrations.
2) Make sure that user profiles and similar pages (member listing pages, for instance) are only accessible by Registered Users.
3) DNN's CAPTCHA won't do squat.

This won't stop the bots but will help ensure your user data is more secure and your site isn't being hit to aid in link farming.

Next, I would try setting up Custom Registration. Note that this won't help in most cases because DNN is still allowing registrations through the default, built-in register URL. Though I did read recently in DNN's JIRA that this had been fixed. It would be worth checking out and possibly upgrading.

I was having this problem at my site, dnndev.com. I'm running DNN Social, so my needs were somewhat different. However I went through the steps I've outlined. When that didn't work, I ended up using XMod Pro (Disclaimer: XMod Pro is my product but I'm sure some of the others forms modules may allow something similar) to create a custom registration form. This put the registration form on a different page that the bots didn't know about. Next I added Google's ReCAPTCHA to the form. This also gives me the option to implement an "honey pot" if needed in the future.

That ensured no new spam bots were registering through my custom form. However, I was still getting spam registrations - not through my new form but from the DNN default form. I couldn't set up any URL routing to avoid it because it is hard-coded into DNN (though this may be corrected in 7.3). What I ended up doing is using the Custom URL Rewriter module in IIS and redirecting the default DNN registration URL's to my custom form. I haven't had any spam registrations since.

HTH,
Kelly

Create simple forms or build complete module solutions XMod Pro is the best-selling forms and views module of all time.
 
New Post
6/19/2014 4:41 AM
 

Hi within the last two weeks, several sites that l administrate have been affected by these spam registrations.  Yesterday l installed the module that Interactive webs have made available for free.  

One site is running CE v7.2.2 and other is running CE v06.02.07, l installed and set up the  Interactive webs module on both sites.  No issues, and also  no further spam registrations.  Hopefully l will roll this out to other sites l also administrate.

If you feel comfortable with running SQL queries then there are some details in the posting that Sebastian included in his reply.

 
New Post
6/19/2014 8:14 AM
 
For me, using Validated membership is an adequate solution. The bot accounts never verify, so occasionally I go to my Users admin screen and click Delete Unauthorized Users followed by Remove Deleted users.

ATM the volumes are low enough for this to be OK. Even at a few hundred per day it would likely be OK.

Is there any estimate from DNN Corp on when there might be a solution baked into the core?

Best wishes,
- Richard
Agile Development Consultant, Practitioner, and Trainer
www.dynamisys.co.uk
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...DNN 6.2 and DNN 7.2 Hacked already... HELP ME....DNN 6.2 and DNN 7.2 Hacked already... HELP ME....


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out