We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 15877
    • 55 Posts
    I am having trouble with a series of EVO websites that got hacked in the last two weeks.

    On this website, I had done the following things:

    • Removed all the files from the server
    • backupped the database
    • Created a new database
    • Reinstalled MODx 1.1 from scratch using the new database
    • Applied the security patch
    • Updated the database with my saved version
    • Reuploaded the files in the /assets directories, making sure every one of them was safe (no .php files)

    I have found (again) files on this one, despite the above actions.

    What I am now doing is checking which files have been uploaded at a given date (28th of november in this case) and deleting them on every Evo website I own.

    Am I missing something?
    Have I forgotten any action?
    How can I spot the file or process they are using to upload the hacking files?

    This question has been answered by multiple community members. See the first response.

    • discuss.answer
      • 2762
      • 1,198 Posts
      the infection is stored inside a plugin code in your database, maybe you have restored the corrupted plugin?
        Free MODx Graphic resources and Templates www.tattoocms.it
        -----------------------------------------------------

        MODx IT  www.modx.it
        -----------------------------------------------------

        bubuna.com - Web & Multimedia Design
        • 13226
        • 953 Posts
        Please read this post and please post / add your problem to Github, here or create a new issue.
          • 15877
          • 55 Posts
          Quote from: banzai at Nov 28, 2016, 03:23 AM
          the infection is stored inside a plugin code in your database, maybe you have restored the corrupted plugin?

          Yes, this is probably the problem.
          I have made a search in my database and found a suspicious code in the QuickEdit plugin.
          Deleted it.

          I will wait to see if this is enough, and if not, perform a full reinstall, but only restore the contents of the database, not the plugins and snippets.

          Thanks for the hint.
            • 36426
            • 197 Posts
            Hi I've had a similar problem. I've reinstalled, patched etc and removed any dodgy looking files. But my database or snippets/modules must have some code still in there as I'm still getting daily Google Console reports of hacked files.

            The URLs all stem from the index page such as:

            /index.php/condition/IefZN/dan/
            /index.php/observe/r+1.pdf=RLRfJ
            /index.php/31/JLeI/

            etc etc. Loads of addresses like that...

            Can anyone please help with how to find where the hacked code is. ClamAV isn't picking anything up. There's no extra users in my database or anything I can see that is obviously unusual.

            Thanks for any help.
              Yorkshire UK based hosting provider: https://www.simulant.uk
            • discuss.answer
              • 13226
              • 953 Posts
              @ jonahnaylor

              This has already been answered here and here

              You have to check and clean the database, otherwise the patch or update to 1.2 won't help you