We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 10076
    • 1,024 Posts
    Hi all, a modx evo 1.05 site has been taken off-line. It has been taken down 2 weeks ago when it was on evo 1.02. So I updated to 1.05 and they took it off line because off spam. What could this be? what do I need to post because I can not give anyone access to the site, because it s not there anymore. I do have a local copy on Xampp
      • 1343 ☆ A M B ☆
      • 2,213 Posts
      What do you mean because of spam? How is this spam being sent? Spam from contact form, spam to site visitors...?
        Patrick | Server Wrangler
        About Me: Website | Tweets |  MODX Hosting
        • 28042 ☆ A M B ☆
        • 24,524 Posts
        You need to be talking to your hosting tech support. You'll need access logs and mail logs. I doubt it's anything to do with MODx itself, although the older version of MODx may have allowed a hacker to insert a script onto your server. You need to try to see if mail is being sent independently from any MODx scripts.

        My first reaction to something like this would be to back up the database and the folders in assets that have my own files, such as images and templates. I'd go through those folders carefully to make sure there's nothing in them besides my own files. I'd completely wipe my website; delete everything and empty the database, using the hosting control panel's file manager to make sure I get everything; mail and all.

        Next, I'd install 1.0.5 on a local machine, import the database back up and moving in my images and template files, and re-run the installer. I'd watch carefully to see how it's behaving from my local site; especially in regards to attempts to send out mail.

        Then I'd install a fresh copy of Evo on the remote site, upload my cleaned images and template files, import the database backup and re-run the installer in upgrade mode. This way I'm going to be sure no hacker's files are left in my web space.
          Studying MODX in the desert - http://sottwell.com
          Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
          Join the Slack Community - http://modx.org
          • 36404
          • 307 Posts
          hi,

          spam problems are usually due to two main reasons, email addresses written in the source code and not secured enough forms

          if you have write email addresses in the pages you may either use a js to write them from an encoded string or use this syntax everybody understands now toto [at] toto [dot] com

          when it comes to forms, there are many solutions
          - captcha, i don't like it for many reasons
          - banished words and domains list, not that efficient and may be a problem depending on your website... domain
          - the one i use with quite success i must say
          i add a text input or a textarea to the top of the form with an empty value and, using css put this empty input 10000px to the left, this way, normal users don't see it and don't fill it either
          first thing i do when dealing with the form data, i check if this input value is empty or not, if not, it's a spam boot, then -> die(); !!!
          i assure you, i was in charge of a website that had tons of spam in a testimonial form and 0 after i had implemented this solution
          to be tried smiley

          have swing
            réfléchir avant d'agir
            • 10076
            • 1,024 Posts
            Hi,

            tnx all for the reaction.
            According to the logfiles, it had to do with an old forum the enduser uploaded and never used!
            As I m not responsible for this site, I never checked untill the enduser asked me to.
            So I just deleted the forum in the domain, en restored the site and all is fine.

            But that solution of that hidden field, i read about it but never saw it detailed, maybe you can give an example cause it sounds really good,

            Frank.

            RIP Steve Jobs
              • 3749
              • 24,544 Posts
              You might look at the SPForm extra. It has a number of anti-spam options -- including the hidden fields trick.
                Did I help you? Buy me a beer
                Get my Book: MODX:The Official Guide
                MODX info for everyone: http://bobsguides.com/modx.html
                My MODX Extras
                Bob's Guides is now hosted at A2 MODX Hosting
                • 5340
                • 1,624 Posts
                If you use eForm add this to the eForm template and hide it in the css using display none
                [[# anti spam Field ]]
                <input value="" name="name2" id="name2" class="text" type="text" eform="Special:date:0"  />
                  • 28042 ☆ A M B ☆
                  • 24,524 Posts
                  I adopted the hidden field that must be empty from SPForm and adapted it to eForm. In my forms I have
                  <input tabindex="50" type="text" name="Last__Name" id="LastName" size=30 autocomplete="off" eform="LastName::0" />
                  

                  The CSS for this moves the field off the screen
                  #contactArea #LastName{position:absolute;text-decoration:underline;background-color:#CC0000;left:0px;top:-500px;width:1px;height:1px;overflow:hidden;}
                  

                  I have a snippet with a function
                  function checkField(&$fields,&$vMsg,&$rMsg) {
                      if(!empty($fields['Last__Name'])) {
                          return false;
                      } else {
                      return true;
                      }
                  }
                  

                  The eForm snippet refers to this function in the &eformOnValidate parameter
                  &eformOnValidate=`checkField`

                  You can either call the snippet that contains the function before the eForm snippet call, or use the &runSnippet parameter in the eForm snippet to load the function so eForm can use it.

                  This snippet just quietly aborts the form with a return of false if the field is filled in; the auto-form-spam bots will fill in all fields and won't notice the CSS actually making the form invisible to normal users. You can add a prompt to indicate the field needs to be left empty if you want to accommodate screen readers and other clients that won't use the CSS.
                    Studying MODX in the desert - http://sottwell.com
                    Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                    Join the Slack Community - http://modx.org