Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Hacked! Hacked!
Previous
 
Next
New Post
11/18/2010 9:55 AM
 
Hi,
I just noticed a new file shirin.aspx in the root of my DNN installation. The file contents say something about hacking, and when I google "shirin" links to shirin under my sites (and other peoples sites) come up.
Luckily it seems that they havent broken anything (yet!), but I have no idea how this is possible for them to do this.
 I've contacted my ISP (WebHostUK) but wonder if there is any known security holes in DNN 5.2.3 ?
It's on the cards to upgrade as I presume that will be the response ... I guess I need to do this, but any help anyone can suggest to help secure the sites in the meantime would be really gratefully received ...
Many thanks
Rob
 
New Post
11/18/2010 10:11 AM
 
It may well be a vulnerability with your ISP. Ensure *you* have a good password! :) That's about all *you* can do. I googled it too - and it seems there are hundreds, if not thousands, of sites affected by this hack. One link I found indicates it allows for homepage defamation - as well as other pages. Not good - would be nice to hear from someone in the know about this thing. Cheers, Duncan.
 
New Post
11/18/2010 10:14 AM
 
I forgot to add the link I found - that had *something* about it - but really nothing about the hack itself. It just seems to show the sites affected (*big* list) - and that it's a homepage and mass page defacement thing. (Did I say defamation by mistake in my last post! - chit I think I did - I meant defacement! :) Cheers, Duncan.
 
New Post
11/18/2010 10:15 AM
 
Damnn!!!! - the link! ... http://www.zone-h.org/archive/notifier=SHIRIN%20HACKER :)
 
New Post
11/22/2010 10:05 AM
 
In the light of this, I discovered that write privs were enabled for the whole hosting area. So I've now had this locked down to read only except the \Portals folder (where users will need to upload docs and images etc). Just wondering then, if this is what everyone else does? What folders need write privs? How does this affect things like DNN upgrade, when DNN presumably writes things all over the place? And adding extensions, when DNN could be writing DLLs to \bin folder and stuff all over the place. Any advice on a secure configuration that people use appreciated. Also, any ideas on how the hacker person was able to write the file in the first place....should I blame DNN or the Hoster, who says they apply all windows patches every weekend ..... And, will they have been able to read the web.config file? and therefore be able to see user data in the database, etc? Should I be worried?! Many thanks all Rob
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Hacked! Hacked!


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out