One of my sites (ModX 0.9.5) just got attacked through a vulnerability with the 777 cache. My info for you is lacking as I was behind a strong proxy (not under my control) when I investigated the attack. So here is what I could determine.
The public end looked normal but carried special characters at the top of the window. I could not determine the true nature of these characters.
The manager would not load properly. It cycled, referencing issues with a file load. Had I been on the ball I would taken screen shots to relay the full message... sorry.
A key note is that the status bar (Firefox) kept popping up references to loading data from ’Bigmam.com’. I do not know these people. Through my host I was able to purge the cache and cleared the problem.
Unfortunately it appears to have infected two of my client’s computers with a virus. My client’s info sounds very sketchy as my system was not infected via IE or Firefox.
I will report back if they can determine the type of the virus... but I am not counting on that info.
I would have taken this as a cache glitch if not for the ’Bigmam.com ’ references.
On a side note... I do not believe that suPHP or PHPSuexec (IXWebhosting) are options for me, but partially following the security advice from
http://wiki.modxcms.com/index.php/Securing_your_site I have changed cache permissions to 755.