We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 6182
    • 32 Posts
    Our site is on a shared server on GoDaddy.

    We cleaned it up, reinstalled and upgraded Modx, purchased security package from GoDaddy and now again we just received notice from Google that hacked content has been detected on our site.

    What more can we do?

    Is there a way to figure how the hack is happening? Maybe a compromised computer that is accessing the Modx manager?

      • 37105
      • 194 Posts
      What exactly is that warning from Google? You are sure it's from Google origin?
        Codeplaza Webdesign: for professional websites at low cost
        • 6182
        • 32 Posts
        yes sure it's from google. because our site has a "this site may be hacked" notice when googling our website.
          • 6182
          • 32 Posts
          it's messages from the Google Console. Should i post our website url and more info?
            • 37105
            • 194 Posts
            Yes please. I am curious about the warning.
              Codeplaza Webdesign: for professional websites at low cost
              • 6182
              • 32 Posts
              Email from Google we received:

              Message type: [WNC-633200]
              Search Console
              Hacked content detected on http://chamah.org/

              To: Webmaster of http://chamah.org/,

              Google has detected that your site has been hacked by a third party who created malicious content on some of your pages. This critical issue utilizes your site’s reputation to show potential visitors unexpected or harmful content on your site or in search results. It also lowers the quality of results for Google Search users. Therefore, we have applied a manual action to your site that will warn users of hacked content when your site appears in search results. To remove this warning, clean up the hacked content, and file a reconsideration request. After we determine that your site no longer has hacked content, we will remove this manual action.

              Following are one or more example URLs where we found pages that have been compromised. Review them to gain a better sense of where this hacked content appears. The list is not exhaustive.

              http://chamah.org/24plus/

              http://chamah.org/41/16248/

              Here’s how to fix this problem:

              1
              Check Security Issues for details of the hack
              Use the example(s) provided in the Security Issues report of Search Console to get an initial sample of hacked pages.
              Security Issues
              2
              Look for other compromised pages or files on your site
              Be sure to check your entire site, including the homepage, for any unfamiliar content that could have been added. The malicious code might be placed in HTML, JavaScript, or other files on your site. It can also be hidden in places you might overlook, such as server configuration files (e.g. .htaccess file) or other dynamic scripting pages (e.g. PHP, JSP). It’s important to be thorough in your investigation.
              3
              Use the Fetch as Google tool to isolate the malicious content
              Because some pages can appear one way to a user and another way to Google crawlers, you can use the Fetch as Google tool to reveal some kinds of hacking. Enter URLs from your site in the tool to see the pages as Google sees them. If the page has hidden hacked content, the tool can reveal that content.
              Fetch as Google
              4
              Remove all malicious content
              You can also contact your hosting provider and ask them for assistance. If you’re having trouble identifying and removing all the content on your site that is compromised, consider restoring an older backed-up version of your site.
              5
              Secure your site from any future attacks
              Identify and fix vulnerabilities that caused your site to be compromised. Change passwords for administrative accounts. Consider contacting your hosting service to get help with the issue.
              6
              Submit a reconsideration request
              Once you fix your site, file for reconsideration to remove this manual action. Include any details or documentation that can help us understand the changes made to your site.
              Reconsideration Request
              Need more help?

              • Read our guide for hacked sites.
              • Learn how to use the Fetch as Google tool in our Help Center.
              • Learn more about reconsideration requests in our Help Center.
              • Ask questions in our forum for more help - mention message type [WNC-633200].
              Google Inc. 1600 Amphitheatre Parkway Mountain View, CA 94043 | Unsubscribe from this type of message
              Add partners who should receive messages for this Search Console account.


                • 6182
                • 32 Posts
                Here's a link to screenshots from the google console
                http://imgur.com/a/4jYLo
                  • 13428 ☆ A M B ☆
                  • 1,031 Posts
                  It looks like your installation still has a backdoor and it is hacked again easy for that reason.

                  Backdoors could be hidden everywhere, so it would be easier to start with a new installation and the content data (site_content and site_tmplvar_contentvalues) of the old site. The TVs have to be created again (or use the original TV tables and make sure that no foreign @EVAL code is in the TV options). All extras have to be installed from the original repositories. And if you copy files from the old installation to the new one: Make sure that no PHP shell or MODX backdoor is copied then (don't copy PHP files). An unknown or a known user with a compromised password could be a backdoor too.
                    • 6182
                    • 32 Posts
                    Is it possible to tell how the hack is getting in? We keep on getting hacked.

                    Looking to hire someone here.
                      • 3749
                      • 24,544 Posts
                      Jako is right that the safest thing is to rebuild the site from scratch. That said, you can check a few things:

                      Look at Manage -> Users and see if there are any users that shouldn't be there.
                      Look for a plugin named core services or something similar
                      Look for plugins you didn't install.
                      Compare the MODX root index.php file with a copy of the original file.
                      Look for extra code in the .htaccess file.

                      Unfortunately, even if you find a back door, you can't be sure it's the *only* back door.

                      If you're on a shared server, it's possible that some other user there (or a hacker of another site there) has gained general access to your server. In that case, it's likely that nothing you do will help, short of starting over at another host.




                        Did I help you? Buy me a beer
                        Get my Book: MODX:The Official Guide
                        MODX info for everyone: http://bobsguides.com/modx.html
                        My MODX Extras
                        Bob's Guides is now hosted at A2 MODX Hosting