Showmedia.com a site i built which runs on MODx Evolution (i believe 1.0.2), has been hacked and now comes up as a "Reported Attack Site". What do I do?? How can I prevent this in the future?? Any help is greatly appreciated.
-
☆ A M B ☆
- 24,524 Posts
1. clean it up; this means find the files that have been infected with bad code (usually involving code added to one of the MODx core files such as the index.php file) and find any extra scripts that have been inserted into your web site's file system. This can best be done by removing everything and restoring to a fairly recent, known good backup. You do make at least occasional backups, don't you? Set your config.inc.php file and the index.php files to be read-only.
2. Upgrade to MODx 1.0.5; this fixes a number of known security issues. Subscribe to the security boards of this forum. Make sure that none of the snippets, modules and plugins that you are using have the code to be pasted into the Manager interface stored as .php files.
3. Make sure your own computer has not been infected with a trojan to capture keystrokes or otherwise track your use, thus getting your FTP and other passwords to gain access to your site. Change all of your site passwords, including your host's control panel (Cpanel, etc).
Thanks. All cleared up. Bit of a scare, that.
-
☆ A M B ☆
- 24,524 Posts
Indeed. I haven't happen to any sites I support - yet. Several big-name hosting companies have had their servers hacked, with thousands of their hosted sites defaced or deleted. When that happens, there's nothing the individual web master can do; if somebody gets root access to a server then they have access to every file on that server, and a server can be hosting 400 sites or more. That includes the CPanel or other control panel as well, and the database.
Backup, people. It's a jungle out there.