Download DOWNLOAD
Forums FORUMS
Blogs BLOGS
Forge FORGE
Help HELP
Marketplace MARKETPLACE
DotNetNuke Home
You are here >   Community > Forums
Register  |  Login

 

DotNetNuke ForumDotNetNuke ForumOur CommunityOur CommunityGeneral Discuss...General Discuss...dotnetnukeskin.com hacked?dotnetnukeskin.com hacked?
Previous
 
Next
New Post
4/24/2006 2:34 AM
 

Ok, I am a new user and have been trying to find skins for my site.  Yesterday dotnetnukeskin.com worked for me but today it would appear the site has been hacked.  I was wondering, can a "skin" make a site any more hackable than normal, or is it about good security practice?

FOR ISLAM
r war will continue against the ones who are against the real religion Islam
<edited>
THIS SITE HACKED

New Post
4/24/2006 2:57 AM
 

Hello, this is not a dotnetnuke issue, it's something else. If you type http://www.dotnetnukeskin.com/default.aspx you'll get to your existing dotnetnuke site. The problem you're seeing is due to a new page called default.htm, which is your sites default document (i.e. when someone types http://www.dotnetnukeskin.com/ they go to http://www.dotnetnukeskin.com/default.htm first). Typically this type of hack has used an automated attack that looks for known webserver issues that haven't been patched, and creates a new page (usually default.htm or index.htm) to deface the site.

To fix this, remove the page, and remove default.htm from the list of default documents. Next make sure you've applied all updates (i.e. via windows update/microsoft update) to stop it happening again. Also, please check any other applications you may be running as I know that there was a recent issue with phpbb that allowed automated hacks using similar text.

Cathal

New Post
4/24/2006 3:04 AM
 

Thanks for the clarification, Cathal.  I have a PHPNuke site that was hit similarly last year when the index.php page got wiped by a script kiddie.  Thankfully nothing else done but it sure puts the wind up ya!  I'm also glad dotnetnukeskins.com is still functioning because I am liking their skins the most at the moment.

Still, in my ignorance, I would like to know if a skin can have anything to do with a site's security?

New Post
4/24/2006 3:34 AM
 

As the skin is the visual interface it is possible to develop a skin that could be a security issue, however that's reasonably unlikely. The majority of dotnetnuke skins use only static html, and the skin objects that we ship with dotnetnuke, for which there are no known issues. If skin developers have added their own active content (i.e .net code) or custom skin objects, it would be possible to introduce code that was not secure, however we've build code into the dotnetnuke core that protects against many common issues at the framework level i.e. there's code that stops most cross site scripting attacks from accessing a users cookie.

Cathal

New Post
4/24/2006 3:43 AM
 
Thanks, Cathal. 
Previous
 
Next
DotNetNuke ForumDotNetNuke ForumOur CommunityOur CommunityGeneral Discuss...General Discuss...dotnetnukeskin.com hacked?dotnetnukeskin.com hacked?

DotNetNuke®, DNN®, and the DotNetNuke logo are trademarks of DotNetNuke Corporation

Hosted by MaximumASP