We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 31902
    • 342 Posts
    We inherited a site that was done on Evolution (so please forgive my ignorance with this package...I usually use Revo) and the site has recently been the subject of an apparent attach by another entity, whereby only some of the pages, when you go to them, then have all of the links within that page link to another domain.

    We've already contacted our server provider and they cannot find any evidence of tampered files, they show no evidence of the offending domain there, nor any kind of alias on the server.

    However, the problem is still there.

    When you first go to the site, the initial page is okay, that is, it is showing the correct domain. When certain pages are clicked on and...if while using Firefox you look closely at the lower left corner of the screen...you can see that the page is first showing the correct domain, then quickly redirecting to the offending domain.

    Can anyone think of anywhere, within Evolution, to look for an apparent breach? I've looked in the .htaccess file but cannot find anything that jumps out as a problem (that I can identify, that is). I see no apparent problems in the source code of the 'good' pages that might be resulting in any redirect.

    Any way a bad guy can set up an alias redirect of only certain pages? Some kind of A Record redirect of only certain pages?

    Yes, we traced the offending domain name to having come through Go Daddy and they are being contacted but I'm not sure that will lead anywhere.

    This has me stumped and need your input. Thank you in advance.

    Using Evolution 0.9.6.3 Rev. 4565
    PHP Version 5.2.10
      • 20413
      • 2,877 Posts
      You are using a REALLY old version of MODX. Every internet software needs to be upgraded on a regular basis.

      I would backup the content. Wipe the server clean.
      Install latest MODX and Snippet versions and set up your site from scratch.
        @hawproductions | http://mrhaw.com/

        Infograph: MODX Advanced Install in 7 steps:
        http://forums.modx.com/thread/96954/infograph-modx-advanced-install-in-7-steps

        Recap: Portland, OR (PDX) MODX CMS Meetup, Oct 6, 2015. US Bancorp Tower
        http://mrhaw.com/modx_portland_oregon_pdx_modx_cms_meetup_oct_2015_us_bancorp_tower
        • 31902
        • 342 Posts
        Thanks, mrhaw. I kept thinking that but this is one complex site and is not in the budget to do that right now. Especially since I'm not that well versed in Evo and upgrading it to whatever the newest version of Evo is would probably destroy what's left of my hair color. I would love to completely redo it in Revo but that is not in the cards right now, either.

        As an aside, we noticed that clearing the site cache fixed the problem. I don't know why or how but it did. Unfortunately, I'm sure it's only temporary and need a permanent fix.
          • 3749
          • 24,544 Posts
          The first place to look is the index.php file.

          Upgrading Evolution is usually pretty straightforward. I upgraded a site from 0.9.6 to 1.0.3 recently with no trouble at all. So you might just back up the whole site and try upgrading, and if it doesn't work, restore the backup.

          I would want to find and fix the intrusion first, however.
            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 1343 ☆ A M B ☆
            • 2,213 Posts
            Hello,

            The upgrade process is easy as Bob noted, but you do need to find the "hole" and plug it first. If you just do a regular upgrade it's likely your site will be hacked again in the future.

            I would suggest doing a clean upgrade, and reviewing any custom functionality/code for problems. If you need help with this let me know.
              Patrick | Server Wrangler
              About Me: Website | Tweets |  MODX Hosting
              • 28042 ☆ A M B ☆
              • 24,524 Posts
              The only caution to upgrading a much older version like this is to not upgrade the Wayfinder and Ditto snippet; both the files in assets/snippets and in the upgrade process where you can select what items to upgrade.

              These have changed over the years to the point where your older snippet calls and parameters may not work, so it's better to leave the original versions in the upgrade, then upgrade them manually later if necessary.

              As far as "no time" or "not in the budget", when your site is being hacked it's a bit naive to think that it won't just get hacked again if you keep using a known vulnerable version of any software. The problem here, however, is most likely to be a script or an individual that has gotten some access to the files and can edit the cache files. An installation that does not have some kind of suexec in the server's configuration must have these files world-writable since the parser's .php file must be able to write them and delete them, so any user that can get access to the files at all can modify them. With suexec, the .php scripts are run as their owner (you), and only that user has write access. It's much more secure; I won't host my own sites on any server that doesn't use it, and make my unhappiness known to any client who insists on using hosting without it.

              You need to make sure there's nothing in the way of rogue scripts that have been added to your files, and you also need to change all of your passwords, for the site's domain control panel (CPanel?), FTP users and all.

                Studying MODX in the desert - http://sottwell.com
                Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                Join the Slack Community - http://modx.org