Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Possibly hacking attempt?Possibly hacking attempt?
Previous
 
Next
New Post
1/18/2010 8:51 AM
 

I found this in my Event Viewer - This file looks supcious but I don't know PHP

[content removed by moderator to stop virus signatures flagging page as suspicious]

Looks like someone is trying to append a file to the default? I assume they were unsuccessful...

AssemblyVersion: 5.2.1
PortalID: 6
PortalName: PokerDIY
UserID: -1
UserName: 
ActiveTabID: 354
ActiveTabName: Welcome
RawURL: /Default.aspx?[URL removed by moderators to prevent virus signature matches]
AbsoluteURL: /Default.aspx
AbsoluteURLReferrer: 
UserAgent: Mozilla/5.0
DefaultDataProvider: DotNetNuke.Data.SqlDataProvider, DotNetNuke.SqlDataProvider
ExceptionGUID: a6b03f52-fd01-46a3-b54e-7d9ba2750c3c
InnerException: parsing "\[QUERYSTRING:CUSTOMPLUGINFILE[]\]" - Unterminated [] set.
FileName: 
FileLineNumber: 0
FileColumnNumber: 0
Method: System.Text.RegularExpressions.RegexParser.ScanCharClass
StackTrace: 
Message: System.ArgumentException: parsing "\[QUERYSTRING:CUSTOMPLUGINFILE[]\]" - Unterminated [] set. at System.Text.RegularExpressions.RegexParser.ScanCharClass(Boolean caseInsensitive, Boolean scanOnly) at System.Text.RegularExpressions.RegexParser.CountCaptures() at System.Text.RegularExpressions.RegexParser.Parse(String re, RegexOptions op) at System.Text.RegularExpressions.Regex..ctor(String pattern, RegexOptions options, Boolean useCache) at System.Text.RegularExpressions.Regex.Replace(String input, String pattern, String replacement, RegexOptions options) at DNNStuff.Aggregator.Aggregator.MakeReplacements_Backward(String s) at DNNCompatibility.ReplaceGenericTokens(Aggregator agg, String text) at DNNStuff.Aggregator.Aggregator.ReplaceAggregatorTabInfoTokens(String text, AggregatorTabInfo ati, Int32 tabNumber) at DNNStuff.Aggregator.Aggregator.GetTabTemplate(Template t, AggregatorTabInfo ati, Int32 tabNumber) at DNNStuff.Aggregator.Aggregator.RenderLayout(Template t) at DNNStuff.Aggregator.Aggregator.RenderTabs() at DNNStuff.Aggregator.Aggregator.Page_Init(Object sender, EventArgs e) at System.Web.UI.Control.OnInit(EventArgs e) at System.Web.UI.UserControl.OnInit(EventArgs e) at System.Web.UI.Control.InitRecursive(Control namingContainer) at System.Web.UI.Control.AddedControl(Control control, Int32 index) at System.Web.UI.ControlCollection.Add(Control child) at DotNetNuke.UI.Modules.ModuleHost.InjectModuleContent(Control content) at DotNetNuke.UI.Modules.ModuleHost.CreateChildControls() at System.Web.UI.Control.EnsureChildControls() at DotNetNuke.UI.Modules.ModuleHost.get_ModuleControl() at DotNetNuke.UI.Containers.Container.get_ModuleControl() at DotNetNuke.UI.Containers.Container.ProcessModule() at DotNetNuke.UI.Skins.Pane.InjectModule(ModuleInfo objModule)
Source: 
Server Name: AS45R95


Entrepreneur

PokerDIY Tournament Manager - PokerDIY Tournament Manager<
PokerDIY Game Finder - Mobile Apps powered by DNN
PokerDIY - Connecting Poker Players

 
New Post
1/18/2010 9:45 AM
 

Hi Rodney,

This particular request is an automated attack against the Subdreamer CMS.  It is similar in form to the other automated attacks that appear with great frequency, such as the SQL injection attempts that we all see in our logs.  It does not represent any appreciable risk from a DotNetNuke core perspective.

I see that your stack trace indicates a Regex failure in the DNNStuff.Aggregator component.  Since I can only address your question from a core perspective, it wouldn't be a bad idea to check with this vendor to ensure that there is no vulnerability there (though this particular form is targeted at PHP and is exceedingly unlikely to ever have non-zero .NET risk).

Hope this helps!

Brandon


Brandon Haynes
BrandonHaynes.org
 
New Post
1/18/2010 10:16 AM
 

Interesting, thanks for the putting my mind at rest.


Entrepreneur

PokerDIY Tournament Manager - PokerDIY Tournament Manager<
PokerDIY Game Finder - Mobile Apps powered by DNN
PokerDIY - Connecting Poker Players

 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Possibly hacking attempt?Possibly hacking attempt?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out