I have seen report of this sort of thing before on hosting forums. It could be a server vulnerability rather than a MODx one. But I am noan expert.
Very likely a server hack and not anything MODx-related. Which is a drag because you don’t know what else these hackers may have installed, so even if you get rid of what you find there may be more mischief elsewhere. The best course of action is to notify your host, change all of your passwords (Control Panel, MySQL, FTP, MODx, etc.), and delete everything and restore from a clean backup.
It looks as if they’ve modified either your cache file, your MODx template, or index.php to add their own (broken) HTML.
9 times out of ten this sort of thing will be due to either a server vulnerability or a compromised password, but make sure that you have the latest version of MODx and have set register_globals to OFF anyway.
Hi
I came here from google. Hope you don’t mind.
My site was hacked yesterday. Same MO. I"m 100% confident that this a bot attack.
In my case it infected WordPress and the Coppermine image gallery.
Coppermine was DOA, not because the hack was malicious, but because it corrupted a file. In the case of WordPress I noticed that as pages were loading the status bar showed transfers from strange websites such as free20.com, bizsomething etc. Also, in IE (I use FF) the format was broken because the hacker’s code screwed up the way IE handles CSS.
The good news - very easy to fix. If you don’t have the files backed up to your hard drive, transfer the infected files there and do a search and replace on all the files and all the folders. Replace the hack code with nothing at all.
The bad news, while this pushed me upgrade Coppermine (I’m hesitant about wordpress due to the high degree i’ve customized it), is that I don’t know how the bastards got in.
The real bad news is that your CMS app, MODx, is also vulnerable. Keep in mind that 99% of infected users won’t know they are infected unless the code corrupts a file and leaves the app inoperable.
@SleepingWolf: Hello and welcome! You’re free to come here from Google or anywhere else. We’re not an exclusive club here.
I’m skeptical that this is an actual vulnerability in MODx, however. If it’s a bot attack, then it may make use of register_globals being left ON to do some sort of cross-site scripting (perhaps through a vulnerability in an RTE package or something like that), but MODx complains pretty loudly if you leave register_globals ON so people doing so really should be scolded. Without more info it’s pretty hard to know, however.
Do you (or anyone else) have any more information on this hack in particular so that we can review it and see how it might affect MODx?
Just a brief FYI: There are tons of new vulnerabilities for both Coppermine and WordPress at
SecurityFocus, but nothing for MODx since the FileDownload snippet hack that was squashed a while back.
I just got rid of it by replacing the siteCache.idx.php file with the backup. Must admit i forgot (uhps) to set registerglobals to of. The host did not react sofar, good news....
For the rest I am not a techie in this matter.
When loading the manager page the page kept reloading it self,with an indication that the formentioned file had an error.
Cheers.
-
MODX Staff
- 10,725 Posts
If this is truly a vulnerability in MODx (or possibly one of the add-ons you’ve chosen), your raw server logs should help reveal the source of it. Look around the time the "hack" occurred and try to find any suspicious looking requests to modx files (i.e. that include strange URLs in the parameters, etc.). Depending on what add-ons you’ve used in your MODx site, one of those could potentially have an as of yet unreported vulnerability, but otherwise, I am doubtful this breach had anything to do with MODx core code itself. However, I’d love to know if you do find anything suspicious; and if you do, we’d appreciate if you would send details via PM first so as not to reveal any potential attack vectors to the public.
I seem to remember someone else having their cache file modified in a similar way by a hacker a long while back. i believe that they were running an old and unpatched version of MODx (0.9.0 I think), and that they also had register_globals set to ON. What version of MODx are you running on this server, and what other scripts do you have installed there?