-
MODX Staff
- 730 Posts
It’s hard to tell how you got hacked, but upgrading to 1.0.5 is considered mandatory so that you’re not leaving yourself open to known vulnerabilities in 1.0.4. (It’s not actually a question of whether you are vulnerable to those ones.. you are!)
I have also seen iframe attacks come from other vectors on a shared hosting system.. a forum or blogging system for example; it can be very hard to track down.
My only other advice at this time is to keep stuff backed up!
Thanks netProphET, unfortunately I’m having to wait until the release of 1.0.6 before I can update as 1.0.5 crashed the site as badly as the hack. The same applies to all my 1.0.4 sites which is far from ideal.
Yes I’ll have to back up the database more regularly.
-
☆ A M B ☆
- 2,213 Posts
If you are able to run 1.0.4 you should be fine running 1.0.5. What kind of error messages did you get with 1.0.5? Can you try a fresh install to see if the issue is upgrade related or server related?
I’ve had no problems upgrading my sites to 1.0.5.
Had similiar situation with one site some time ago. Remember to change your FTP password. This types of hacks are often related to trojans on computer stealing FTP account data from FTP client. Maybe scanning your machine for that won’t be a bad idea.