We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 53017
    • 2 Posts
    Some of my sites got hacked in the last couple of days.

    I rolled back to a 2 month old backup and upgraded to 2.6.5

    This cured the main site but the manager remains compromised and unusable immediately taking you to dodgy external websites when you click anywhere on the interface.

    I can't see in the code how this is happening, it seems to wrap the manager interface in an iframe which links to external sites.

    I am not using the gallery extra and have grepped for phpthumb in the existing extras, none seem to use it.

    Can anyone tell me how the manager could be wrapped in an dodgy iframe like this?

    Ta
    Peter


    This question has been answered by multiple community members. See the first response.

    • discuss.answer
      • 22840
      • 1,572 Posts
      Make sure you have deleted everything in the core >> Cache folder manually
      • discuss.answer
        • 33337
        • 3,975 Posts
        I think you should upload fresh /manager and /connectors folders from latest zip. (replacing the old one completely, not overwrite.)

        This should fix the issue. Although I think it might not be 100% clean backup.
          Zaigham R - MODX Professional | Skype | Email | Twitter

          Digging the interwebs for #MODX gems and bringing it to you. modx.link
          • 53017
          • 2 Posts
          Did both those and the system seems to be working ok now smiley

          Thanks
          Peter