Small width layout Medium width layout Maximum width layout Small text Medium text Large text
     Search
Downloads Downloads Directory Directory Forums Forums Forge Forge Blogs Blogs        Marketplace Marketplace Careers Program Careers
Community › Forums Register  |  

Affordable ASP.NET Hosting Service
  Ads  
Active Modules -- Active Forums for DotNetNuke
 


  Sponsors  

Meet Our Sponsors

Mad Development is a full service interactive agency focusing on the merge of design, technology, e-commerce, and affiliate marketing by providing total website solutions.
SteadyRain
DataSprings - Great Ideas. Always Flowing.
R2integrated - formerly bi4ce
Jango Studios - Skins, Modules and Hosting for DotNetNuke
eUKhost.com is commited to offer exceptional UK Windows Web Hosting solutions with quality 24x7 technical support.Our plans support ASP.Net, ASP, ASP.NET Ajax extensions, XML, MSSQL, MySQL, PHP,DNN, multiple domains and Shared SSL as standard.
 


DotNetNuke Forums
 
  Forum  DotNetNuke® Pro...  Feedback Module...  Severe Security Issue
Previous Previous
 
Next Next
New Post 9/1/2008 1:16 PM
User is offline ErikVB
3048 posts
www.apollo-software.nl
4th Ranked










NiRe: Severe Security Issue 

Nick, please check out our security policy here: http://www.dotnetnuke.com/News/SecurityPolicy/tabid/940/Default.aspx

especially this info :

"We request that all suspected issues/security scan results get emailed to our security alias displayed below [...]:

security@dotnetnuke.com

Any information submitted to this alias is kept confidential and is only viewed by members of the DotNetNuke Security Task Force, and will not be discussed outside this group without permission from the person/company who submitted the information. Confirmed issues will be assigned a level to indicate their relative severity and potential impact. This information will be made available via the security blog, forum posts, and where judged necessary, an email bulletin."

Please, use the security email address for any future communication about possible security issues


Erik van Ballegoij,
a view from my attic, my personal blog

The personal blog of Erik van Ballegoij

 
New Post 9/2/2008 2:11 AM
User is offline abstraction
61 posts
10th Ranked


Re: Severe Security Issue 

 Sanjay Mehrotra wrote
 

"One thing I have done is stopped PHP on my server which will more than likely help with allot of this."
 

Nick - I believe you've solved your own problem. Like I'd posted on the other thread which you made on the forums, the culprit is likely to be PHP and NOT DNN. You can take the exact script you've posted here and run it on any of the websites that have the feedback module installed (mothership included) and you will not see your problem.
Someone probably did a scan on your machine and discovered that you have PHP installed and was able to take advantage of that via your website.

I've done my limited research based on what you've posted so far and Cathal will probably comment on this shortly too.

My problem with your original post is making it sound like feedback module is the culprit when you're not sure - or let me put it another way - Can you prove 100% that the feedback module caused your server to be hacked?

I'm not going to get into the semantics but as mentioned before, any security issues need to be addressed differently than simply posting on a thread without any proper validation.

Sanjay

Well regarding PHP I guess only time will tell whether the site is safe or not now, I'm reserving judgement as the last site this happened on was completely hosted and one would presume that it would have been allot more secure than the one i'm hosting myself.

If DotNetNuke wasn't eleviated in anyway, so what you are suggesting is that any site running PHP can be hacked extremely easily in this way?

 

"But with that aside, I think that one of the possible holes was actually this Feedback module."

That is what I said, and I chose my words carefully, I said that it is a possible hole, and the reason for that was that it was being targeted, so I can assure you that you misunderstood there by not reading thoroughly.  If on the other hand you are referring to the subject of the thread then I think it's a bit generic and anyone interested enough would actually read it before casting judgement themselves.

 
New Post 9/2/2008 2:14 AM
User is offline abstraction
61 posts
10th Ranked


Re: NiRe: Severe Security Issue 

 ErikVB wrote
 

Nick, please check out our security policy here: http://www.dotnetnuke.com/News/SecurityPolicy/tabid/940/Default.aspx

especially this info :

"We request that all suspected issues/security scan results get emailed to our security alias displayed below [...]:

security@dotnetnuke.com

Any information submitted to this alias is kept confidential and is only viewed by members of the DotNetNuke Security Task Force, and will not be discussed outside this group without permission from the person/company who submitted the information. Confirmed issues will be assigned a level to indicate their relative severity and potential impact. This information will be made available via the security blog, forum posts, and where judged necessary, an email bulletin."

Please, use the security email address for any future communication about possible security issues

Cheers Eric, I shall keep that for future reference, but I'd love to know the number of your users that have actually read those documents prior to posting any queries.

 
New Post 9/2/2008 11:23 AM
User is offline cathal connolly
2756 posts
www.cathal.co.uk
5th Ranked










Re: NiRe: Severe Security Issue 

This is not an issue, as the path would not be resolved as it does not contain an asp.net page extension prior to the querystring i.e. an extension ending .aspx/.ashx/.asmx/.axd . I also checked the last 2 releases of the feedback module (going back to1/30/2007) and netiher has code that references a querystring, request or paramters variable called include_path. I also checked a few recent core releases and they do not reference it either, so what your'e seeing is random url requests (much like the recent sql worm) that will not cause any harm and simply get logged as invalid requests. As per other posters, I would recommend that you mail the security@dotnetnuke.com so that the security team can process any reported problems - i've been off for a few days holiday but there are at least another 6 people who monitor that alias.

And and as for your question, we've received messages from 55 different people so far this calendar year (we've responded to a couple of hundred reports and requests).

Cathal

 
Previous Previous
 
Next Next
  Forum  DotNetNuke® Pro...  Feedback Module...  Severe Security Issue
 


Forum Policy

These Discussion Forums are dedicated to the discussion of the DotNetNuke Web Application Framework.

For the benefit of the community and to protect the integrity of the project, please observe the following posting guidelines:

1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DotNetNuke.
2. Discussion or promotion of DotNetNuke product releases under a different brand name are strictly prohibited.
3. No Flaming or Trolling.
4. No Profanity, Racism, or Prejudice.
5. Site Moderators have the final word on approving/removing a thread or post or comment.
6. English language posting only, please.

 


Faculty of Graduate and Postdoctoral Studies
At the graduate level, the University of Ottawa offers more than 180 graduate certificates, master's degrees and PhDs, as well as interdisciplinary programs such as Women's Studies and Canadian Studies. Many postdoctoral opportunities are available in both the sciences and the humanities. For further information, please consult the site of the Faculty of Graduate and Postdoctoral Studies.
www.grad.uottawa.ca
Vekkin Solutions
Vekkin Solutions provides complete website solutions and custom module development to churches and small businesses.
www.vekkin.com
Powered by Adcuent®.Com
Adcuent® Consulting & Technology offers custom development web applications and hosting projects under the brand of Powered by Adcuent®.Com
www.adcuent.com

DotNetNuke Corporation   Terms Of Use  Privacy Statement
DotNetNuke®, DNN®, and the DotNetNuke logo are trademarks of DotNetNuke Corporation
Hosted by MaximumASP