DNN Forums

Ask questions about your website to get help learning DNN and help resolve issues.

hacked with unknown image

Sort:
You are not authorized to post a reply.
Page 1 of 212 > >>





Growing Member





    an image shows up at the the bottom right of the screen no link to anywhere. Initially it was redirecting to some page here chianxiaoshuo.net 

    I can't find any trace on the website. 

    I can see it when I go to https://momzey.com but it does appear on the same website with a different subdomain https://2019.momzey.com 

    any help to figure out where it may be coming from would be greatly appreaciated

    It is acting as if it is coming from DNS  but there are no records in the DNS to suggest it. 

     






    Growing Member





      check ModuleSettings and PortalSettings tables for references to the code that is being added
      e.g.
      SELECT * FROM [ModuleSettings] where [SettingValue] like '%todelete%'






      Veteran Member





        Hi Franc,
        Most likely the vulnerability that has been used is Telerik related.
        The script most used widely will upload an aspx file in the root. This file then allows to place content. In the version history you will see that the content has no author.

        So, you need to remove the malicious aspx files and upgrade.
        The aspx files that are legit are the default.aspx, Errorpage.aspx and keepalive.aspx. All others are suspect and need investigation. I have seen instances where dotnetnuke.aspx was placed which looks legit but was not.
        Tjep's digital agencyRegards,
        Tycho de Waard

        Tjep's digital agency
        We just love DNN
        https://www.tjeps.com





        Growing Member





          Thanks  for the help, I only have the 3  legit files you mentioned. Also this issue first appeard on 4/14/2022 I don't see any files of anytype that have been added or edited recently 

          not sure if the hack would have updated the modified date on the folder 






          Growing Member





            I did run the query for module setting and portal setting did not return any info for '%todelete%'

            I am also not sure what I am looking for. I can be just a lose nut in front of the CRT 






            Veteran Member





              No, the folder date won't tell you much.
              If you have rdp, you could try a search for .aspx in general.
              Sometimes they create a folder /video and place a file there.

              Tjep's digital agencyRegards,
              Tycho de Waard

              Tjep's digital agency
              We just love DNN
              https://www.tjeps.com





              Growing Member





                I did search for *.aspx in the root folder and found 58 items with ASPX file type on different folders. Most look like they are associated with different modules. Don't know what to look for inside these files. 

                last modified 8/1/2021 HabuMiyar.aspx 

                 






                Growing Member





                  I did search for *.aspx in the root folder and found 58 items with ASPX file type on different folders. Most look like they are associated with different modules. Don't know what to look for inside these files. 

                  last modified 8/1/2021 HabuMiyar.aspx 

                   






                  Veteran Member





                    If you want, I could take a look at things for you. Either via FTP or if you feel uncomfortable with that, we could screen share so you can watch my every move :-) 

                    You can reach out to me at [email protected]

                    Tjep's digital agencyRegards,
                    Tycho de Waard

                    Tjep's digital agency
                    We just love DNN
                    https://www.tjeps.com





                    Growing Member





                      i'll send you remote desktop credentials 

                       

                      You are not authorized to post a reply.
                      Page 1 of 212 > >>

                      These Forums are dedicated to the discussion of DNN Platform.

                      For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

                      1. If you have (suspected) security issues, please DO NOT post them in the forums but instead follow the official DNN security policy
                      2. No Advertising. This includes the promotion of commercial and non-commercial products or services which are not directly related to DNN.
                      3. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
                      4. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
                      5. No Flaming or Trolling.
                      6. No Profanity, Racism, or Prejudice.
                      7. Site Moderators have the final word on approving / removing a thread or post or comment.
                      8. English language posting only, please.

                      Would you like to help us?

                      Awesome! Simply post in the forums using the link below and we'll get you started.

                      Get Involved