I received the following message from Google Webmaster a few days ago, telling me there are suspected hacking on the Embedded101.com site:
========================================================
Google has detected that your site may have pages added by a third party. These pages may contain spammy or malicious content which violate our Webmaster Guidelines.
Typically, the offending party gains access to an insecure directory that has open permissions. Many times, they will upload files or modify existing ones, which then show up as spam in our index.
Sample URLs:
========================================================
When I check the site, I found some files were uploaded to the site's root folder by hacker. The files are in set of 2, using the same file name with different extensions, such as the following:
- 4FaEH.asp
- 4FaEH.gif
Basically, it's a black hat SEO practices. The .asp file contains script that direct site visitor to other URL.
I've recently updated the site to the latest version of DNN 7.4.1. These hacking activities happen after the site is upgraded to 7.4.1.
It's this a known vulnerability for DNN?
Is there some settings or configuration I can change to prevent this from happening?
Thanks in advance for you help!
Sam