Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Hacked on 8.2.2 - New exploits on smtp mail??Hacked on 8.2.2 - New exploits on smtp mail??
Previous
 
Next
New Post
2/22/2019 2:20 AM
 

I believe this is a new exploit...

Since Feb 21, 2019, one of my DNN sites running on 8.2.2 is sending spams using the smtp relay setting stored in DNN. The email header looks like this, which definitely is generated inside DNN. and the spam are sent to the users inside DNN.

Return-Path: <example@example.com>

Received: from exampleServer ( exampleServer [xx.xx.xxx.xxx]) by xxxxxxx with SMTP;

Fri, 22 Feb 2019 12:43:00 +0800

MIME-Version: 1.0

Sender: "DotNetNuke" <example@example.com>

From: "example" <example@example.com>

To: example@example.com

Upon checking

1. event logs, there is no other login attempts beside super admin account.

2. None of the DNN files are being modified since 2017.

3. all are default DNN module except one PropertyAgent module by Ventrian.

4. Security Analyzer found nothing suspicious...

 


 

 

 


Thanks,
George

Where to eat? Visit GoEatOut for Food Promotion in Kuala Lumpur.
 
New Post
2/22/2019 4:42 AM
 
This sound to me more like an issue of the mail server configuration. Is "exampleServer [xx.xx.xxx.xxx]" your web server running DNN, and is there a mail server (which?) installed on the same machine?

Happy DNNing!
Michael

Michael Tobisch
DNN★MVP

dnn-Connect.org - The most vibrant community around the DNN-platform
 
New Post
2/25/2019 12:18 AM
 

Hi Michael,

There's no mail server running on the dedicated DNN server.  The DNN smtp setting is set to another external mail server.

The weird thing is after I removed all the smtp setting in DNN, changed the admin and super user accounts email address (only 2 accounts inside), the spam still delivering from/to the same email address.

I tried to use the security analyzer to search the email address and keywords, nothing is found.

When I check the DNN files in server, non of the files are being modified since mid of 2017.

and then I also blocked outbound firewall TCP port 25 and 2525 (special smtp port for the mail server), still the spam email still happening. I can't stop them.

I actually starting to worry that other DNN in the same server are compromised and the smtp data is actually stored in other DNN folders.

 


 

 


Thanks,
George

Where to eat? Visit GoEatOut for Food Promotion in Kuala Lumpur.
 
New Post
2/25/2019 2:21 AM
 
What evidence is there that the spam actually originates from your server?

Is it possible that the true source is a server not under your control emitting forged headers that look the same as yours?

Best wishes,
- Richard
Agile Development Consultant, Practitioner, and Trainer
www.dynamisys.co.uk
 
New Post
2/25/2019 6:16 AM
 
George,

as you blocked any outgoing port on the firewall, the DNN installation should not be able to send emails, correct? Therefore I agree with Richard, there is no evidence that the spam originates from your DNN installation.

Again: Is "exampleServer [xx.xx.xxx.xxx]" your web server running DNN?

Happy DNNing!
Michael

Michael Tobisch
DNN★MVP

dnn-Connect.org - The most vibrant community around the DNN-platform
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Hacked on 8.2.2 - New exploits on smtp mail??Hacked on 8.2.2 - New exploits on smtp mail??


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out