Quote from: refriend at Apr 01, 2007, 10:23 AM
To follow up from my last message...
I am afraid I don’t have much to tell as my client’s corporate tech support person (whom he claims to be the best in the city) has convinced him of the evils of hidden malicious code in opensource. An example of this attitude’s prevailing effect is that any attempt from me to investigate the problem is returned by my client’s answer of ’who is responsible?’ and ’who will pay?’. So maybe you can appreciate my lack of answers.
ROFLMAO; I needed a great laugh to start the day and make me spit coffee all over myself. I love how we "hide" code in source that is completely available to the public; i.e. open source. DOH!
Quote from: refriend at Apr 01, 2007, 10:23 AM
All directories were set per 0.9.5 instructions (i.e. cache 0777).
Ummm, where are these instructions and who should be shot for telling you to set all MODx dirs to 0777??? Permissions completely depend on the environment you are running in. I for instance run some sites with dirs to 0700 and files to 0600, others with 755 and 644, and even others with 775 and 664. It depends on file and group ownership, what user is executing the PHP process, etc. But I can tell you that using 0777 and 0666 across the board on a MODx site is not correct and should never be done...that would make those dirs and files writable by any user on that machine. If it’s a shared Linux host, you can see the obvious problem with that.
Quote from: refriend at Apr 01, 2007, 10:23 AM
The website is hosted by IXWebHosting and is running PHP Version 4.4.6 & mysql 4.1.20 on Apache Release 10331100.
I’ve set ’php_flag register_globals Off’ in the .htaccess file (in home directory) as the IXWebhosting is globally set to On. On a side note, I just found that the home .htaccess file was missing. It is (and was) present in /manager. I am surprised by this as I had configured the home .htaccess file during the site’s install in order to clear the ModX ’Global Registers Set to On’ warning.
Other:
I asked my client if he could have brought the virus with him on a usb drive and he said no (take that for what it is worth). He does have virus protection on both infected computers (home and work)... though I can’t find out what the software is. Neither my computer (through IE or Firefox) nor IXWebhosting system was infected when we viewed the site and manager (nor did I get any virus/trojan warnings).
My conclusions:
1. I can not confirm if a virus was transmitted through my site or if it was coincidence.
2. The site’s cache and .htaccess were modified. It would appear to have been malicious due to the calls to bigmam.com.
3. I am lacking a lot of information.
I am sorry not to have provided more info. Are the any ideas on how to better secure the cache without the services of PHPSuexec or suPHP?
-Rich
Yeah, definitely don’t set permissions on all directories to 777; find out what the minimum permissions you need are and use those (likely 775 dirs and 664 files), and get a host and server admin with a clue. If they can’t tell you what happened, and run the server with register_globals=On still, that’s a good warning sign indicating you should likely run away.