We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 6038
    • 228 Posts
    I don’t remember adding these, but some interesting stuff has happened in my weblogin chunks and snippets.
    In the registration form this hidden variable appears not once, but twice:
    <input type="hidden" name="phpMyAdmin" value="f3961184ba27f76dd4bb6bac17cb5356" />


    and in one of my chunks, a link:
    <li><a href="[~84~]?bus_id=[+bus_id+]&phpMyAdmin=f3961184ba27f76dd4bb6bac17cb5356">View Business Details</a>


    Obviously, this is very concerning - either:
    - my mind is really fading and I put them there myself ages ago, for some unknown reason (very unlikely)
    - my web host added them somehow?????!!??!! (very unlikely)
    - using phpmyadmin has added it somehow? ( seems unlikely)
    - my site has been hacked? ( seems most likely!)

    How could this strange key get in there? And what could someone do with the key?
    Has this ever happened to anyone else?

    I’m using MODx Evo 1.0.3 (recently upgraded from 0.9.6)
    Weblogin 1.3.1
    PHP 5.2.11 (safe mode was recently just turned off)
    mysql 5.0.86
    Apache 2.0

      • 7455
      • 2,204 Posts
      its plesk:
      http://modxcms.com/forums/index.php?topic=21033.0
      I think you made a backup using phpmyadmin tru plesk?
      and then imported that again?

      Dimmy
        follow me on twitter: @dimmy01
        • 6038
        • 228 Posts
        Dimmy - thank you - that is a relief!

        Only one person reported that it affected their website in a negative way, and that sounded like it may have to do with other issues, so it doesn’t seem to be too hazardous.
        I didn’t restore a back up, but my host did move it from a windows to linux server, and that may have involved doing so.

        You have no idea how pleased I am to know that it is not that the site has been hacked!