DNN Forums

Ask questions about your website to get help learning DNN and help resolve issues.

URL Injection Vulnerabilty

 6 Replies
 3 Subscribed to this topic
 40 Subscribed to this forum
Sort:
Author
Messages
Growing Member
Posts: 38
Growing Member

Hi, we recently had someone create a folder and an aspx file in the root of dnn site via URL injection. This site is an old version "DNN 7.0"  that was due to be upgraded. 

Another Dnn site ver 9.1.1  site had a unknown text file in the root which is obviously an attempt to test an attack. Has anyone experienced similar or  any knowledge of how this may have been done??

is there something that can be done to secure the root folders/prevent url injection or test a site to see if secure?, will an upgrade sort the problem out.

Any advice is appreciated at this point

Growing Member
Posts: 38
Growing Member
Also where can I find older upgrade downloads
Veteran Member
Posts: 1246
Veteran Member
MVP
MVP
You're an MVP!
They are on GitHub organized like this: https://github.com/dnnsof....Releases.Archive.6x

Change the 6 to the series that you want.
Veteran Member
Posts: 1246
Veteran Member
MVP
MVP
You're an MVP!
You will find them in order, along with other stuff, at https://github.com/dnnsoftware
Veteran Member
Posts: 1182
Veteran Member
MVP
MVP
You're an MVP!
Stuart,

please also consider that the hack could come from another source - e.g. weak FTP setup/password.

Happy DNNing!
Michael

Michael Tobisch
DNN★MVP

DNN Connect
Growing Member
Posts: 38
Growing Member
Cheers guys.
Hi Michael, defo worth looking closer at Firewall logs, even though we have never allowed FTP and none other than ICT staff connect to the server using RDP
New Around Here
Posts: 5
New Around Here
Hi any news about this hack?
thanks

These Forums are for the discussion of the open source CMS DNN platform and ecosystem.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. If you have (suspected) security issues, please DO NOT post them in the forums but instead follow the official DNN security policy
  2. No Advertising. This includes the promotion of commercial and non-commercial products or services which are not directly related to DNN.
  3. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  4. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  5. No Flaming or Trolling.
  6. No Profanity, Racism, or Prejudice.
  7. Site Moderators have the final word on approving / removing a thread or post or comment.
  8. English language posting only, please.

Would you like to help us?

Awesome! Simply post in the forums using the link below and we'll get you started.

Get Involved