Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...II've Been Hacked!
Previous
 
Next
New Post
8/7/2006 5:56 AM
 

Hi,

I woke this morning to find one of my DNN2 servers hacked by NobodyCoder from Iran. About 20 customers in total.

Luckily, on further investigations, the hacker has not done as much damage as he could have done.

He basically deleted all the files in the root directory and replaced them with files calling for an end to the war between Israel and Palestine. When I say he didn't do as much damage as he could have, I mean that he didn't delete any directories, only files in the root.

So, I now need to find out how it happened.

I have trawled the internet and come accross a posting, http://www.betterhumans.com/blogs/simon/archive/2006/05/01/The-hack.aspx , where he says that if he didn't have write permissions, he would not have been able to perform the hack.

So, in your opinions, do you think he managed to hack DotNetNuke or has he hacked the platform?

Personally, I think he hacked the platform as the second he would have deleted default.aspx and replaced it with his own, he would have lost DNN.

Anyone else been hacked by this guy recently?

Thanks

Trev


www.taxiroute.co.uk - Get a Fare Price!
 
New Post
8/7/2006 11:22 AM
 

Well, this just keeps getting more and more interesting....

Reported the hacking to my ISP this morning and to be fair to them they have been very thorough in their investigations...

What they have found out is this.

1. The damage was done via FTP not DNN
2. The hacker connected using the correct username and password first time. Not a brute force attack.
3. The hacker connected to the server from MY LAPTOP!!!! at 8.27am this morning - IP Address has been confirmed.
4. I had my Windows & Router firewall switched off.

So, Ok, yes I am an idiot. I had been working yesterday on getting my SlingBox working for external access and forgot to switch them back on.

Notwithstanding this, how the hell did he get onto my PC and get hold of my FTP username and password?? The only place I can think this is stored is within Site Settings of Dreamweaver. I know I had my firewall switched off but I am running a laptop with all the latest patches and Hot Fixes, so there must be a hole in XP somewhere that this guy has managed to find. Obviously usually hidden by the firewall.

I'm no security expert, as you can see by me leaving my firewall off, but this seems a very clever attack. He must have found my external router, managed to get onto my internal wireless network, find my laptop, get control of it, find my username & password, decrypt it from Dreamweaver and then launch from my laptop to the ISP server. Not a small task.

Anyway, I've certainly learnt a few lessons today.

Hope this story might help someone in the future!

Trev


www.taxiroute.co.uk - Get a Fare Price!
 
New Post
8/7/2006 11:27 AM
 

Latest Update.....

Looks like getting hold of a Dreamweaver username and password is not difficult....

check this out.... http://www.apptools.com/password.php

Trev


www.taxiroute.co.uk - Get a Fare Price!
 
New Post
8/9/2006 2:59 PM
 
Interesting read... ;0
 
New Post
8/9/2006 3:45 PM
 

Yes, saved passwords are EVIL!  If you're not going to require the user to key it every time, then what's the point??? 

Because U & P is so easy to brute force, and because sadly it's become common--yea even expected/required by lazy users--to save passwords....well the US government is now requiring all US financial institutions to implement multi-factor authentication (U & P plus PIN, last statement balance, biometric scan, etc)...  I just wonder hong long it'll be before lazy users circumvent even those.  Then all of us (even those of us too smart to save passwords) will have to suffer another round of complications to do menial tasks.   

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...II've Been Hacked!


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out