Please take a look through the security notices here and you’ll find all the info you need. It’s not necessary to uninstall the Reflect snippet, since the installed code is perfectly safe. You should, however, delete assets/snippets/reflect/snippet.reflect.php (or rename it to have a .txt extension), which is the code that was provided to be copied and pasted into the manager and is not needed for Reflect to run, and you also should make sure that register_globals is OFF.
If you’ve already been hacked, I suggest that you delete all of the files on the server and reinstall from a backup (use the new 0.9.6.3 installer to start and then copy your image and other files). Change all of your passwords (FTP, Control Panel, database, and MODx). And did I mention making sure that register_globals is set to OFF?
May be they already deleted the file for you?
Is that applying to all hosts?
-
MODX Staff
- 12,272 Posts
How does treating files as PHP5 solve the register globals being on issue?
Ryan Thrash, MODX Co-Founder
Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me