Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...default.aspx overwritten, could it be a security issue?default.aspx overwritten, could it be a security issue?
Previous
 
Next
New Post
7/28/2016 2:07 AM
 

Dear All,

lately one of my DNN websites had an issue where the default.aspx got overwritten with the same html output that it should generate for the home page. while the original markup got lost and replaced with the same home page HTML output plus some google ad. i had to upgrade it from 7.1.1 to 7.4.2

have anyone faced this issue before?

 

 
New Post
7/28/2016 4:44 AM
 
The question is: How did it get overwritten? You should check your FTP logs and secure them if it comes from this side. And: in this case, it is not a DNN issue.

Happy DNNing!
Michael

Michael Tobisch
DNN★MVP

dnn-Connect.org - The most vibrant community around the DNN-platform
 
New Post
7/31/2016 4:28 AM
 

Hi Michael,

No it is not an FTP, none of these ports are opened on my server, and I only access it through secured RDP after i open VPN to the hosting network. I believe it is a security issue with DNN 7.1.1 but still couldn't figure it.

 
New Post
7/31/2016 7:28 AM
 
please download and install security analyser module and run it on your site.
https://github.com/DNNCommunity/Secur...

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
8/1/2016 8:42 AM
 

Thanks Sebastian, 

I found many aspx files uploaded to /portals/0/ folder that are not related to DNN source or any of the modules, kind of hacking attempts. and these files contains Antak webshell and other webshell made by China. 

strange isn't it?! is there any security issue in DNN 7.1.1 that allow anonymous to upload aspx files or zip files ?

I know about the CKEditor dialog security issue but I thought this is an old issue that has been resolved already. beside CKEditor provider is not installed 

any feedback ?

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...default.aspx overwritten, could it be a security issue?default.aspx overwritten, could it be a security issue?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out