DNN Forums

Ask questions about your website to get help learning DNN and help resolve issues.

Exploits?

Sort:
You are not authorized to post a reply.





New Around Here





    We have a DNN 7.2.2 web site running on Microsoft Azure Cloud (3 servers / load balanced).  The site code is in cloud storage, and is copied to and cached on each web servers as they are commissioned.

    Last week, on at least one of the servers, anyone accessing the site, upon clicking on any link within the site would get a new window directing them to download malware of some kind.  The link was to: onvictinitor.com/afu.php?zoneid=*&var=* where zoneid and var were each 7 digit integers (not that it matters).

    This link was displaying for many different users on many different computers in many different office locations.  It was definitely the DNN site that was the source of this.

    We decommissioned all three servers, then recommissioned new ones and the problem was gone.  This indicates someone injected javascript into our DNN site.  This also means that the hack was done on one or more of the individual cloud web servers, as by simply killing the server and rebuilding a new one we removed the malicious script by restoring the code from cloud storage.

    We have taken the entire site offline knowing that the exploit is likely to occur again.  This is causing our company serious issues.

    We see that over time there have been DNN exploits, but would like to know more specifically what exploit was used to accomplish this.  We have not had the opportunity to upgrade our DNN platform, but it just seems strange that someone would be able to accomplish something like this.

    Until we know for sure what the cause was, we are unable to use DNN - regardless of the version.  

    I have been unable to find articles related to this type of exploit and how it would be accomplished.

    Please help.






    Growing Member





      As your DNN is very dated, there is a number of possible causes. On https://www.dnnsoftware.c...rity/security-center you can verify that there have been several critical issues.
      You really need to upgrade. If you are running DNN Sharp modules, you can not upgrade to 9.4 yet (expected feb 2020 DNN sharp is up to scratch) but at least upgrade to 9.3.2.
      If possible upgrade to the latest 9.4

      Beware of the fact that 9.2 deprecated a lot of code, so testing should be done.





      Veteran Member





        Please report security issues to [email protected].

        And, as Tycho mentioned ... UPGRADE!
        Joe Craig
        DNN MVP
        Patapsco Research Group





        New Around Here





          @D3VO64 
          have you found a solution? Patch?

          thanks

          You are not authorized to post a reply.

          These Forums are dedicated to the discussion of DNN Platform.

          For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

          1. If you have (suspected) security issues, please DO NOT post them in the forums but instead follow the official DNN security policy
          2. No Advertising. This includes the promotion of commercial and non-commercial products or services which are not directly related to DNN.
          3. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
          4. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
          5. No Flaming or Trolling.
          6. No Profanity, Racism, or Prejudice.
          7. Site Moderators have the final word on approving / removing a thread or post or comment.
          8. English language posting only, please.

          Would you like to help us?

          Awesome! Simply post in the forums using the link below and we'll get you started.

          Get Involved