We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 21969
    • 4 Posts
    Has anyone encountered any security problems using the base href tag?

    I implemented FURLs the other day. In the process I added <base href="[(site_url)]" /> to my template headers. Had FURLs working perfectly. The next morning though I discovered that the site had been hacked and whoever got in has somehow changed the base href tag so that the URLs now point to someone completely different.

    Anyone else experience this?

    Basically, I’m trying to track down if it is a security issues with MODx and the base href tag OR (I’m leaning toward this one) if someone truly hacked into the server and made changes.

    Any insight is much appreciated.
      • 25663 MODX Staff
      • 12,272 Posts
      What version of MODx are you running, what other scripts are you running, and is register_globals set to ON in your PHP configuration?
        Ryan Thrash, MODX Co-Founder
        Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
        • 22303 MODX Staff
        • 10,725 Posts
        The site_url is set dynamically based on how you access the web site. Apparently, your site is accessible from this other tld and it was accessed from that url. If you are caching the page, whatever url was used to access the page when it was first cached is what the value will be until the page cache is again cleared and re-generated.
          • 21969
          • 4 Posts
          So if I’m reading this correctly, site_url isn’t pulled from my configuration file every time. If someone/somewhere else has access to the site, then the page is cached with their URL. So, which solution is best? Hardcoding the base href (which won’t be very friendly since it’s on a test server right now and not referencing the actual domain name. Or, using the uncached snippet option : base href="[!getSiteUrl!]" (found here: http://modxcms.com/forums/index.php?topic=31825.0 ) ?

          ----
          BTW: sorry about the double post. I figured I posted in the wrong place, tried to post it in the right place, then couldn’t figure out how to delete what I thought was the wrong one. Won’t happen again, captain.