We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 31255
    • 118 Posts
    Read article about LizaMoon mass-injection. Is Evo/Revo safe for these injection.

    Here`s the article:http://community.websense.com/blogs/securitylabs/archive/2011/03/31/update-on-lizamoon-mass-injection.aspx

    [update] Or... is this just April Fools’ Day hoax.
      Tassu, webmaster of Valokammi
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      If it’s an SQL injection problem as they seem to think, then MODx itself is quite safe from it. Any custom or third-party applications that don’t thoroughly validate and sanitize all user input would be vulnerable, but that’s not something MODx has any control over. Kind of like the scam emails that offer to share x million dollars with you, I have to wonder who isn’t aware of this sort of thing by now, that somebody is obviously writing scripts that don’t take care of the problem.

      Interesting that all of the databases they’ve found this in are MSSQL databases.
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org