DNN Forums

Ask questions about your website to get help learning DNN and help resolve issues.

URL Injection Vulnerabilty

Sort:
You are not authorized to post a reply.





Growing Member





    Hi, we recently had someone create a folder and an aspx file in the root of dnn site via URL injection. This site is an old version "DNN 7.0"  that was due to be upgraded. 

    Another Dnn site ver 9.1.1  site had a unknown text file in the root which is obviously an attempt to test an attack. Has anyone experienced similar or  any knowledge of how this may have been done??

    is there something that can be done to secure the root folders/prevent url injection or test a site to see if secure?, will an upgrade sort the problem out.

    Any advice is appreciated at this point






    Growing Member





      Also where can I find older upgrade downloads





      Veteran Member





        They are on GitHub organized like this: https://github.com/dnnsof....Releases.Archive.6x

        Change the 6 to the series that you want.
        Joe Craig
        DNN MVP
        Patapsco Research Group





        Veteran Member





          You will find them in order, along with other stuff, at https://github.com/dnnsoftware
          Joe Craig
          DNN MVP
          Patapsco Research Group





          Veteran Member





            Stuart,

            please also consider that the hack could come from another source - e.g. weak FTP setup/password.

            Happy DNNing!
            Michael

            Michael Tobisch
            DNN★MVP

            dnnWerk Austria
            DNN Connect





            Growing Member





              Cheers guys.
              Hi Michael, defo worth looking closer at Firewall logs, even though we have never allowed FTP and none other than ICT staff connect to the server using RDP





              New Around Here





                Hi any news about this hack?
                thanks
                You are not authorized to post a reply.

                These Forums are dedicated to the discussion of DNN Platform.

                For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

                1. If you have (suspected) security issues, please DO NOT post them in the forums but instead follow the official DNN security policy
                2. No Advertising. This includes the promotion of commercial and non-commercial products or services which are not directly related to DNN.
                3. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
                4. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
                5. No Flaming or Trolling.
                6. No Profanity, Racism, or Prejudice.
                7. Site Moderators have the final word on approving / removing a thread or post or comment.
                8. English language posting only, please.

                Would you like to help us?

                Awesome! Simply post in the forums using the link below and we'll get you started.

                Get Involved