Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Hosting Issues...Widespread Hacking...or just coincidence?Hosting Issues...Widespread Hacking...or just coincidence?
Previous
 
Next
New Post
2/15/2012 1:26 PM
 
Glenn,
Very interested in your commment about qustionable PortalAliases - I have seen that also on several instances that were either recent new install of 6.x - altho we've also seen some very odd aliases in some 5.x instances. Is this issue something that is recurring, e.g. any more issues after you removed the odd aliases?
 
New Post
2/15/2012 4:03 PM
 
@Tony Valenti

What versions are affected by this ? 6 ? 5 ?

thanks
 
New Post
2/15/2012 6:44 PM
 

Evening All,

I wanted to report back on my original post, but some issues remain unresolved with individual hosting companies. Most of my client's affected sites are back up, but Midphase seems to have been the hardest hit. My client had a Wordpress site on their hosting account and this is what was hacked and launched a DoS attack on the rest.

GoDaddy 4GH hosting has unreliable nodes (based on their own admission) and is migrating some sites to new servers. But also by their own admission ASP.NET sites will not perform well because they are throttling CPU and Memory in IIS for "fairness". I will report on their responses when my issues are finalized.

MyHosting.com had outages too, and recommended that I "look into memory leak issues" in DNN 6.1.3. Their worker processes were not automatically restarting, and sites had been down for hours until we prompted them to restart and "wait 24 hours for your issue to be resolved".

Other issues are still being resolved, but obviously widespread DoS attacks were at the root. And I haven't found a single DNN installation that I manage at fault for vulnerability. Kudos to the DNN team's rapid updates and Microsoft's proactive security advisories to help keep us all protected.

--Phil

 
New Post
2/24/2012 2:52 PM
 

Hello Costas, 

Currently for all of our customers, we are recommending that they are on version 5.6.7 or 6.1.3. Right now, those are the only secure versions of DNN in my mind. 

Think of it as Windows updates, they constantly come out with security updates and if you miss out and don't install one. You run the risk of allowing someone to exploit that vulnerability and possibly harm your desktop. Your DotNetNuke installation is really no different.

If you have any questions, whether you host with us or not, feel free to give me a call or email. 


Johnny Gregory Senior Technology Consultant o: 1.877.743.8366 x701115 skype: johnny.managed Managed.com ​ Advanced CMS Hosting and Support for Business Websites DNN - ElcomCMS - WordPress - nopCommerce - Drupal Need a Developer? DeveloperMatch.com
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Hosting Issues...Widespread Hacking...or just coincidence?Hosting Issues...Widespread Hacking...or just coincidence?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out