We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 25663 MODX Staff
    • 12,272 Posts
    I doubt your host will add it though niemi, if it’s not already there.
      Ryan Thrash, MODX Co-Founder
      Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
      • 21483
      • 32 Posts
      "It’s already enabled on my server." kiss
        • 25663 MODX Staff
        • 12,272 Posts
        Note to self: pay attention next time.
          Ryan Thrash, MODX Co-Founder
          Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
          • 7923
          • 4,213 Posts
          If you can set CHMOD value for files over 644 or for folders over 755, it’s not in use.


            "He can have a lollipop any time he wants to. That's what it means to be a programmer."
            • 21483
            • 32 Posts
            Doze, then I understand nothing. I CAN set CMOD value over 644/755 but the support at servage tells me this:

            "Hello xxx,

            Yes you can run suPHP and PHPsuexec for your domain kreativpotens.dk , for that register global must be set to off which has already done from control panel.

            Thank you.


            Kind regards,
            xxx, Servage Hosting"
              • 28042 ☆ A M B ☆
              • 24,524 Posts
              What does your phpinfo() say?

              Reports -> System information, then "view" the phpinfo. Near the top, it should say say something like "CGI" or "FastCGI" in the Server API line, about four lines down (right after the Configure Command line)
                Studying MODX in the desert - http://sottwell.com
                Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                Join the Slack Community - http://modx.org
                • 21483
                • 32 Posts
                Server API = Apache 2.0 Handler
                  • 24757
                  • 9 Posts
                  One of my sites (ModX 0.9.5) just got attacked through a vulnerability with the 777 cache. My info for you is lacking as I was behind a strong proxy (not under my control) when I investigated the attack. So here is what I could determine.

                  The public end looked normal but carried special characters at the top of the window. I could not determine the true nature of these characters.

                  The manager would not load properly. It cycled, referencing issues with a file load. Had I been on the ball I would taken screen shots to relay the full message... sorry.

                  A key note is that the status bar (Firefox) kept popping up references to loading data from ’Bigmam.com’. I do not know these people. Through my host I was able to purge the cache and cleared the problem.

                  Unfortunately it appears to have infected two of my client’s computers with a virus. My client’s info sounds very sketchy as my system was not infected via IE or Firefox.

                  I will report back if they can determine the type of the virus... but I am not counting on that info.

                  I would have taken this as a cache glitch if not for the ’Bigmam.com ’ references.

                  On a side note... I do not believe that suPHP or PHPSuexec (IXWebhosting) are options for me, but partially following the security advice from http://wiki.modxcms.com/index.php/Securing_your_site I have changed cache permissions to 755.
                    • 21483
                    • 32 Posts
                    So, sottwell what can you make of that piece of information?

                    Anybody here know anything about applying that patch on http://wiki.modxcms.com/index.php/Securing_your_site ?
                      • 25663 MODX Staff
                      • 12,272 Posts
                      refriend, were you ever able to determine how someone modified your site cache files?
                        Ryan Thrash, MODX Co-Founder
                        Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me