Hi All,
Please forgive the "bulletin" format of my post. I expect that many people will have questions regarding this so I've tried to organize things so they can be quickly read.
If you are not running DotNetNuke 6.1.3/5.6.7, you should upgrade immediately as your website contains critical security vulnerabilities.
Regarding the hacking...
There is a security bug that affects old versions of DNN which allows anyone to upload files to your website.
There are hacker groups which are actively exploiting this vulnerability and creating DNN-botnets. The botnets are used to launch large-scale denial of service attacks.
When a site is being actively leveraged in the attack, there are a few key things you'll notice:
1) CPU will spin up to 100%.
2) Network utilization will spin up to 100%
While most hosting providers have network-based limitations in place to prevent a single server from maxing out the network, it is much more difficult to prevent 10, 100, or even 1000 random servers (depending on the size of the hosting provider) from saturating the hosting provider's own network when the botnet is being leveraged.
In order to combat this, we've built the following:
1) A DotNetNuke security notification system. Every week customers receive a report which informs them of any vulnerabilities which impact their version of DotNetNuke.
2) A "Malicious File Checker" which actively look for the "fingerprints" of a hacked site and responds accordingly.
3) A server-level and site-level CPU and bandwidth monitor which allows us to rapidly respond if a site is being leveraged.
If you suspect your website may have been compromised:
1) Upgrade to the latest version of DotNetNuke.
2) Scan your website for files that don't look right. Specially, look for:
a) PHP files that you did not create.
b) ASP/ASPX files that you did not create.
c) .TXT files that you did not create.
d) Multi-extension files which contain a semicolon. For example, "Google.asp;.jpg"
If you are hosted with PowerDNN and need assistance in upgrading:
1) Please open a support ticket with PowerDNN and our team will assist you through the process.
If you are NOT hosted with PowerDNNand need assistance in upgrading:
Please find a consultant or developer to assist with your needs.