DNN Forums

Ask questions about your website to get help learning DNN and help resolve issues.

hacked with unknown image

 15 Replies
 5 Subscribed to this topic
 40 Subscribed to this forum
Sort:
Page 1 of 212 > >>
Author
Messages
Growing Member
Posts: 48
Growing Member

an image shows up at the the bottom right of the screen no link to anywhere. Initially it was redirecting to some page here chianxiaoshuo.net 

I can't find any trace on the website. 

I can see it when I go to https://momzey.com but it does appear on the same website with a different subdomain https://2019.momzey.com 

any help to figure out where it may be coming from would be greatly appreaciated

It is acting as if it is coming from DNS  but there are no records in the DNS to suggest it. 

 

Growing Member
Posts: 85
Growing Member
check ModuleSettings and PortalSettings tables for references to the code that is being added
e.g.
SELECT * FROM [ModuleSettings] where [SettingValue] like '%todelete%'

Veteran Member
Posts: 838
Veteran Member
3 Helpful Replier
Helpful Replier
Thanks for being such a helpful replier!
New Poster
New Poster
Congrats on posting!
Hi Franc,
Most likely the vulnerability that has been used is Telerik related.
The script most used widely will upload an aspx file in the root. This file then allows to place content. In the version history you will see that the content has no author.

So, you need to remove the malicious aspx files and upgrade.
The aspx files that are legit are the default.aspx, Errorpage.aspx and keepalive.aspx. All others are suspect and need investigation. I have seen instances where dotnetnuke.aspx was placed which looks legit but was not.
Growing Member
Posts: 48
Growing Member

Thanks  for the help, I only have the 3  legit files you mentioned. Also this issue first appeard on 4/14/2022 I don't see any files of anytype that have been added or edited recently 

not sure if the hack would have updated the modified date on the folder 

Growing Member
Posts: 48
Growing Member

I did run the query for module setting and portal setting did not return any info for '%todelete%'

I am also not sure what I am looking for. I can be just a lose nut in front of the CRT 

Veteran Member
Posts: 838
Veteran Member
3 Helpful Replier
Helpful Replier
Thanks for being such a helpful replier!
New Poster
New Poster
Congrats on posting!
No, the folder date won't tell you much.
If you have rdp, you could try a search for .aspx in general.
Sometimes they create a folder /video and place a file there.

Growing Member
Posts: 48
Growing Member

I did search for *.aspx in the root folder and found 58 items with ASPX file type on different folders. Most look like they are associated with different modules. Don't know what to look for inside these files. 

last modified 8/1/2021 HabuMiyar.aspx 

 

Growing Member
Posts: 48
Growing Member

I did search for *.aspx in the root folder and found 58 items with ASPX file type on different folders. Most look like they are associated with different modules. Don't know what to look for inside these files. 

last modified 8/1/2021 HabuMiyar.aspx 

 

Veteran Member
Posts: 838
Veteran Member
3 Helpful Replier
Helpful Replier
Thanks for being such a helpful replier!
New Poster
New Poster
Congrats on posting!

If you want, I could take a look at things for you. Either via FTP or if you feel uncomfortable with that, we could screen share so you can watch my every move :-) 

You can reach out to me at [email protected]

Growing Member
Posts: 48
Growing Member

i'll send you remote desktop credentials 

 

Page 1 of 212 > >>

These Forums are for the discussion of the open source CMS DNN platform and ecosystem.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. If you have (suspected) security issues, please DO NOT post them in the forums but instead follow the official DNN security policy
  2. No Advertising. This includes the promotion of commercial and non-commercial products or services which are not directly related to DNN.
  3. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  4. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  5. No Flaming or Trolling.
  6. No Profanity, Racism, or Prejudice.
  7. Site Moderators have the final word on approving / removing a thread or post or comment.
  8. English language posting only, please.

Would you like to help us?

Awesome! Simply post in the forums using the link below and we'll get you started.

Get Involved