HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...dotnetnukeskin.com hacked?dotnetnukeskin.com hacked?
Previous
 
Next
New Post
4/24/2006 2:34 AM
 

Ok, I am a new user and have been trying to find skins for my site.  Yesterday dotnetnukeskin.com worked for me but today it would appear the site has been hacked.  I was wondering, can a "skin" make a site any more hackable than normal, or is it about good security practice?

FOR ISLAM
r war will continue against the ones who are against the real religion Islam
<edited>
THIS SITE HACKED

 
New Post
4/24/2006 2:57 AM
 

Hello, this is not a dotnetnuke issue, it's something else. If you type http://www.dotnetnukeskin.com/default.aspx you'll get to your existing dotnetnuke site. The problem you're seeing is due to a new page called default.htm, which is your sites default document (i.e. when someone types http://www.dotnetnukeskin.com/ they go to http://www.dotnetnukeskin.com/default.htm first). Typically this type of hack has used an automated attack that looks for known webserver issues that haven't been patched, and creates a new page (usually default.htm or index.htm) to deface the site.

To fix this, remove the page, and remove default.htm from the list of default documents. Next make sure you've applied all updates (i.e. via windows update/microsoft update) to stop it happening again. Also, please check any other applications you may be running as I know that there was a recent issue with phpbb that allowed automated hacks using similar text.

Cathal

 
New Post
4/24/2006 3:04 AM
 

Thanks for the clarification, Cathal.  I have a PHPNuke site that was hit similarly last year when the index.php page got wiped by a script kiddie.  Thankfully nothing else done but it sure puts the wind up ya!  I'm also glad dotnetnukeskins.com is still functioning because I am liking their skins the most at the moment.

Still, in my ignorance, I would like to know if a skin can have anything to do with a site's security?

 
New Post
4/24/2006 3:34 AM
 

As the skin is the visual interface it is possible to develop a skin that could be a security issue, however that's reasonably unlikely. The majority of dotnetnuke skins use only static html, and the skin objects that we ship with dotnetnuke, for which there are no known issues. If skin developers have added their own active content (i.e .net code) or custom skin objects, it would be possible to introduce code that was not secure, however we've build code into the dotnetnuke core that protects against many common issues at the framework level i.e. there's code that stops most cross site scripting attacks from accessing a users cookie.

Cathal

 
New Post
4/24/2006 3:43 AM
 
Thanks, Cathal. 
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...dotnetnukeskin.com hacked?dotnetnukeskin.com hacked?


Forum Policy

These Discussion Forums are dedicated to the discussion of the DotNetNuke Web Application Framework.

For the benefit of the community and to protect the integrity of the project, please observe the following posting guidelines:

1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DotNetNuke.
2. Discussion or promotion of DotNetNuke product releases under a different brand name are strictly prohibited.
3. No Flaming or Trolling.
4. No Profanity, Racism, or Prejudice.
5. Site Moderators have the final word on approving/removing a thread or post or comment.
6. English language posting only, please.

Attend A Webinar
Free Demo Site
Download DotNetNuke Professional Edition Trial
Have Someone Contact Me
Have Someone Contact Me

Like Us on Facebook Join our Network on LinkedIn Follow DNN Corporate on Twitter Follow DNN on Twitter

Advertisers

DotNetNuke Scoop!

Sponsors

DotNetNuke Corporation

DotNetNuke Corp. is the steward of the DotNetNuke open source project, the most widely adopted Web Content Management Platform for building web sites and web applications on Microsoft. Organizations use DotNetNuke to quickly develop and deploy interactive and dynamic web sites, intranets, extranets and web applications. The DotNetNuke platform is available in a free Community and subscription-based Professional and Enterprise Editions with an Elite Support option. DotNetNuke Corp. also operates the DotNetNuke Store where users purchase third party apps for the platform.