Our site is on a shared server on GoDaddy.
We cleaned it up, reinstalled and upgraded Modx, purchased security package from GoDaddy and now again we just received notice from Google that hacked content has been detected on our site.
What more can we do?
Is there a way to figure how the hack is happening? Maybe a compromised computer that is accessing the Modx manager?
What exactly is that warning from Google? You are sure it's from Google origin?
Codeplaza Webdesign: for professional websites at low cost
yes sure it's from google. because our site has a "this site may be hacked" notice when googling our website.
it's messages from the Google Console. Should i post our website url and more info?
Yes please. I am curious about the warning.
Codeplaza Webdesign: for professional websites at low cost
-
☆ A M B ☆
- 1,031 Posts
It looks like your installation still has a backdoor and it is hacked again easy for that reason.
Backdoors could be hidden everywhere, so it would be easier to start with a new installation and the content data (site_content and site_tmplvar_contentvalues) of the old site. The TVs have to be created again (or use the original TV tables and make sure that no foreign @EVAL code is in the TV options). All extras have to be installed from the original repositories. And if you copy files from the old installation to the new one: Make sure that no PHP shell or MODX backdoor is copied then (don't copy PHP files). An unknown or a known user with a compromised password could be a backdoor too.
Is it possible to tell how the hack is getting in? We keep on getting hacked.
Looking to hire someone here.
Jako is right that the safest thing is to rebuild the site from scratch. That said, you can check a few things:
Look at Manage -> Users and see if there are any users that shouldn't be there.
Look for a plugin named core services or something similar
Look for plugins you didn't install.
Compare the MODX root index.php file with a copy of the original file.
Look for extra code in the .htaccess file.
Unfortunately, even if you find a back door, you can't be sure it's the *only* back door.
If you're on a shared server, it's possible that some other user there (or a hacker of another site there) has gained general access to your server. In that case, it's likely that nothing you do will help, short of starting over at another host.