Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Upgrading DNN P...Upgrading DNN P...Site Setting fail for 7.3.1 upgradeSite Setting fail for 7.3.1 upgrade
Previous
 
Next
New Post
9/1/2014 5:15 PM
 

Hi guys,

two things. I noticed that three of my sites have had false registration attacks in the last 10 days. This only happened after I upgraded to 7.3.1. I had presumed that it was just my crazy ex-brother in law who is upset I published family law documents about his sister, my ex wife. But one of the sites would be completely unknown to him. It was a temporary site that we only used for a week. I had forgotten all about it until I checked the logs last night and found it had 8,000 registrations now. I see there is a security patch for capchta on log in. So is there a wider problem of some more organised group attacking late release DNN sites?

One of the sites that is being attacked like this is my www.instantbi.com site that was just upgraded. When I went in to turn regstrations off until I install the captcha I get a site settings fail as per the message below. Has anyone seen this before? Anyone know what I need to do to fix it?

Thanks

Best Regards 
Peter 

AssemblyVersion:7.3.1

PortalID:0

PortalName:Instant Business Intelligence

UserID:1

UserName:host

ActiveTabID:39

ActiveTabName:Site Settings

RawURL:/Admin/SiteSettings.aspx

AbsoluteURL:/Default.aspx

AbsoluteURLReferrer:http://www.instantbi.com/Products/BuyNow/SeETL/Emailer.aspx

UserAgent:Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.143 Safari/537.36

DefaultDataProvider:DotNetNuke.Data.SqlDataProvider, DotNetNuke

ExceptionGUID:6618c463-18db-4556-a876-6039bc63c363

InnerException:Selection out of range Parameter name: value

FileName:

FileLineNumber:0

FileColumnNumber:0

Method:Telerik.Web.UI.RadComboBox.PerformDataBinding

StackTrace:

Message:

DotNetNuke.Services.Exceptions.PageLoadException: Selection out of range
Parameter name: value ---> System.ArgumentOutOfRangeException: Selection out of range
Parameter name: value
   at Telerik.Web.UI.RadComboBox.PerformDataBinding(IEnumerable dataSource)
   at Telerik.Web.UI.RadComboBox.OnDataSourceViewSelectCallback(IEnumerable data)
   at System.Web.UI.DataSourceView.Select(DataSourceSelectArguments arguments, DataSourceViewSelectCallback callback)
   at Telerik.Web.UI.RadComboBox.OnDataBinding(EventArgs e)
   at Telerik.Web.UI.RadComboBox.PerformSelect()
   at System.Web.UI.WebControls.BaseDataBoundControl.DataBind()
   at Telerik.Web.UI.RadComboBox.DataBind()
   at DotNetNuke.Web.UI.WebControls.DnnSkinComboBox. (EventArgs e)
   at System.Web.UI.Control.LoadRecursive()
   at System.Web.UI.Control.LoadRecursive()
   at System.Web.UI.Control.LoadRecursive()
   at System.Web.UI.Control.LoadRecursive()
   at System.Web.UI.Control.LoadRecursive()
   at System.Web.UI.Control.LoadRecursive()
   at System.Web.UI.Control.LoadRecursive()
   at System.Web.UI.Control.LoadRecursive()
   at System.Web.UI.Control.LoadRecursive()
   at System.Web.UI.Control.LoadRecursive()
   at System.Web.UI.Control.LoadRecursive()
   at System.Web.UI.Control.LoadRecursive()
   at System.Web.UI.Control.LoadRecursive()
   at System.Web.UI.Page.ProcessRequestMain(Boolean includeStagesBeforeAsyncPoint, Boolean includeStagesAfterAsyncPoint)
   --- End of inner exception stack trace ---

 

Source:

Server Name: ss2-001



Best Regards Peter
 
New Post
9/1/2014 5:20 PM
 

Just found this....so yes..there seems to be people out there who like to create fake registrations to DNN sites.

I should have searched first.

https://support.managed.com/kb/a2000/how-to-prevent-stop-registration-spam-from-fake-accounts-dnn.aspx


Best Regards Peter
 
New Post
9/2/2014 3:28 AM
 
there is some protection in DNN 7.3.2, I suggest upgrading your sites.

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
9/14/2014 11:58 AM
 

Hi Sebastian,
thanks...yes...Once I realised it was some organised guys doing this I found that there was some new protection in 7.3.2.

I only just got through with the 7.3.1 upgrade....I have to do all the usual download/backup etc to make sure the upgrade does not harm my sites....took me about 4.5 days to get from my older versions up to 7.3.1. Hopefully it will be quick to get to 7.3.2.

My sites now have thousands of these userids...is there a mass delete function anywhere? When I go into user admin it looks like I can not mass delete userids.

Thanks

Peter 


Best Regards Peter
 
New Post
9/14/2014 1:37 PM
 
Peter,

upgrade from 7.3.1 to 7.3.2 should be easy - backup files and database, unzip unblocked upgrade package into the DNN install folder and browse site (I don't expect problems with 3rd party extensions, but if you applied TurboDNN, you should run TurboUnschema first).

There are known issues with SiteSettings in DNN 7.3.2, please run script from https://dnnscript.codeplex.com/releas... after the upgrade.
To delete spam users, please read . Script may be obtained from https://dnnscript.codeplex.com/releas....

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Upgrading DNN P...Upgrading DNN P...Site Setting fail for 7.3.1 upgradeSite Setting fail for 7.3.1 upgrade


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out