A site I’ve developed has been locked out by hosting because of a spamming/hacking issue. Still waiting for hosting company to get back to me about what the issue is.
In December 2008, I did a total reinstall because of a similar issue- It was caused by the snippet/reflect problem we had then. I found it under Security Notifications. I did as indicated by the security issue notification. I actually deleted the file snippet.reflect.php.
However, now I’m seeing the following in the Page activity ont the site. Does anyone know what this is?
massexcellence.com//assets/snippets/reflect/config.php
massexcellence.com//assets/snippets/reflect/snippet.reflect.php
massexcellence.com//assets/import/configinc.php
What exactly is the functionality contained in the reflect folder? Can I just get rid of it entirely without causing a problem?
I know you recommend that globals be off but I don’t have control of this. In December, couldn’t get the host to turn off register globals so I took their recommendation and added a php.ini file to shut them off.
Apparently, none of this helped as I’m back in the same position I was in before.
This is extremely frustrating and I’m getting leary of using modx in the future if it’s going to cause me to have these issues. Does anyone have any suggestions? I know I’m probably missing something here.
Keep in mind that you may have another problem entirely. All of us with MODx sites are getting constantly probed for the Reflect vulnerability. The probes are completely harmless once you’ve removed or renamed the php file and, even with the php file there, you were still safe if you had register_globals off (and, if there’s no way to turn it off, you should change hosting services). New script-kiddies are discovering the reflect vulnerability every day and their harmless probes will probably continue for some time.
So, your current problems could very well have nothing to do with Reflect or MODx (and I should mention that Reflect is part of a MODx add-on, not MODx). You could be the victim of a persistent email spammer, a cross-site scripting attack, a brute-force crack of your username and password, etc. etc.
Let us know what your host says and what the symptoms are. The odds are good that it has nothing to do with MODx.