Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Performance and...Performance and...Blackhole Exploit (virus)Blackhole Exploit (virus)
Previous
 
Next
New Post
7/10/2012 10:10 AM
 

My site keeps getting infected with the Exploit Blackhole Exploit Kit 2195.  It seems to like attacking the initWidget.js and the dnn.js

The company that hosts my site just tells me to change my FTP password, but after a couple of days it finds my new directory and infects my site.

Any suggestions to help me remedy this problem?

 

Patrick J. Briggs

 
New Post
7/10/2012 11:31 AM
 

There is a known security issue on Paralells PLESK Hosting Appplication, that should be closed.  There is an KB article on the Paralells page.  Use long passwords with lettery, numbers and symbols as your passwords.

Check the system about trojans, use antivirus application, close not used ports with your firewall, monitor your server and blog IP's from hackers.

 
New Post
7/10/2012 11:39 AM
 

all variants of the blackhole explout kit attempt to inject obfuscated iframed links of themselves into js files - this is not application specific, it simply searches and updates the first few it finds -this is the mechanism by which it attempts to spread (often known as "drive-by-downloads" as the aim is to infect your sites users and not the site itself).

Blackhole is a constantly evolving toolkit and uses a lot of tangents to install - at present the most succesful ones use recently patched java exploits - the best thing you can do is ensure that your anti-virus scanner is up to date and do a full scan, add another antivirus tool such as malwarebytes to pick up any other missed items, patch known targets such as Adode Flash, Adobe Acrobat and Java, and run windows update. In addition as a best practice I would recommend changing your FTP and user passwords.


Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
7/10/2012 12:08 PM
 
excellent point by Matthias - plesk has been a target with blackhole recently (and unfortunately there is also apparently an unpatched plesk update for sales- http://krebsonsecurity.com/2012/07/plesk-0day-for-sale-as-thousands-of-sites-hacked/ )

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
7/10/2012 12:17 PM
 
Matthias Schlomann wrote:

There is a known security issue on Paralells PLESK Hosting Appplication, that should be closed.  There is an KB article on the Paralells page.  Use long passwords with lettery, numbers and symbols as your passwords.

 -- My host does indeed use PLESK.  I did change my password to letters, numbers but the infection found the new directory after a couple of days.

 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Performance and...Performance and...Blackhole Exploit (virus)Blackhole Exploit (virus)


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out