Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Performance and...Performance and...Malicious code keeps getting inserted in skin filesMalicious code keeps getting inserted in skin files
Previous
 
Next
New Post
10/2/2014 4:03 AM
 

hi,

My website keeps getting code that links to other website (like <a href="http://www.pornxxx.com/" title="porn">porn</a>) inserted on to aspx skin files. Sometimes it changes the encoding of the aspx files to ANSI instead of UTF-8.  

This happens with DNN 5 as well as after upgrading to DNN 7 (07.02.01 (367) as of now).

This happens with old server as well as after moving the code to newly installed server (both Windows Server 2008 R2 with active Kasperky protection).

We many modules installed, both developed by ourselves and downloaded from  codeplex.

What should I check to find out what causes this?

Thank you.

Suxipo

 
New Post
10/2/2014 8:34 AM
 
Are you sure the bad HTML is in the skin and not on the PC? This probably sounds funny but my last company had an internal virus that somehow swapped out links to ones like that but it was on the client side, not the server.

If it is in the skin, I would review security to ensure someone isn't gaining access to the server. Internal or external. Maybe set up monitoring.

Lastly, I would check permissions on the skins folder and any custom modules that allow uploads. Make sure you do not allow any .net file to be uploaded as per the settings within the website.

Mark
 
New Post
10/2/2014 10:08 AM
 
I had a similar problem recently. I was looking for some information on the network. This information helped me a little.
Thanks
 
New Post
10/3/2014 4:49 AM
 
Mark Eckeard wrote:
Are you sure the bad HTML is in the skin and not on the PC? This probably sounds funny but my last company had an internal virus that somehow swapped out links to ones like that but it was on the client side, not the server.

If it is in the skin, I would review security to ensure someone isn't gaining access to the server. Internal or external. Maybe set up monitoring.

Lastly, I would check permissions on the skins folder and any custom modules that allow uploads. Make sure you do not allow any .net file to be uploaded as per the settings within the website.

Mark

 Thank you Mark for your inputs.

The bad HTML is in random locations within the skin files on the Server. And it doesnt happen to just 1 one file. Usually in the C:\inetpub\wwwroot\Portals\1\Skins\SKINNAME\index.ascx or similar files in other portals.

I will try to monitor this server more closely to ensure no one else except me and the other developer are able to access this server. This happened to older server as well as newly setup server though so I doubt it is the cause.

I am not sure what are the correct permissions for skin folders. What are the least required permissions for these folders?

About the "Make sure you do not allow any .net file to be uploaded as per the settings within the website.", how exactly should I do this?

Suxipo
 
New Post
10/3/2014 7:17 AM
 
Suxipo,

have you checked if these manipulated skin files were uploaded via FTP? When DNN security is OK, this is very often the reason, so you should check your FTP logfiles.

Best wishes
Michael

Michael Tobisch
DNN★MVP

dnn-Connect.org - The most vibrant community around the DNN-platform
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Performance and...Performance and...Malicious code keeps getting inserted in skin filesMalicious code keeps getting inserted in skin files


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out