We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 37550 ☆ A M B ☆
    • 711 Posts
    Hi,

    I thought I would share this with you all and for anyone that continues to run an old version of Evolution, this morning we have detected that a few of our customer sites who are running MODx old versions of MODx Evolution < 1.0.7 have had their site hacked through the exploits in the previous versions which has resulted in a lot of spam trying to go through our servers.

    I would highly recommend to those that have not got round to upgrading to do so straight away we have had several sites affected so far and are now working with customers to make sure they upgrade to the latest version straight away.

    Also the infected files being injected into the site are called wp-conf.php so it may be worthwhile checking your site for theses files if you run an old version also.

    Hope that helps

    Aaron
      http://www.onesmarthost.co.uk
      UK MODX Hosting with love.
      • 5340
      • 1,624 Posts
      Do you know how they do it? Was it the Forgot Manager Login?
        • 37550 ☆ A M B ☆
        • 711 Posts
        Hi Cipa,

        I have just checked through our logs and can confirm it was via the Forgot Manager Login, the hacker was also quite quick with a couple of calls to that they then had access to the website and also placed on the website a file called formajax.php.

        Thanks Aaron
          http://www.onesmarthost.co.uk
          UK MODX Hosting with love.
          • 3749
          • 24,544 Posts
          Were the injected files in the MODX root?

            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 37550 ☆ A M B ☆
            • 711 Posts
            Hi Bob

            They were a little scattered

            domainname.com\wp-conf.php
            domainname.com\wwwroot\wp-conf.php

            Then there were some random file names, and also a lot of new index.php files in sub folders like assets.

            So far since the weekend we seem to be in good shape, disabling the forgot manager plugin and upgrading sites may have helped there.

            We are also migrating to new Windows 2008 servers which will have some improved security to stop the PHP process writing to certain folders however a hacker could still exploit a site if its out of date and inject the file into the writeable cache folder.

            Aaron
              http://www.onesmarthost.co.uk
              UK MODX Hosting with love.
              • 22427
              • 793 Posts
              It is worth to be mentioned that Evolution 1.0.8 is out since yesterday.
              May be someone adds a 1.0.8 subforum to the Evo forum?
                • 16278
                • 928 Posts
                Quote from: ottogal at Jan 09, 2013, 05:11 AM
                It is worth to be mentioned that Evolution 1.0.8 is out since yesterday.
                May be someone adds a 1.0.8 subforum to the Evo forum?

                I would have thought an actual announcement of the release by MODX central would be appropriate, really. I only came to realize that 1.0.8 existed through Twitter. I'd expect to see it here first, but had to dig around to find anything about it. Nothing in Announcements or Security Notices, nor in sites' Security Notices feed.

                ??? KP
                  • 16610
                  • 634 Posts
                  Quote from: kp52 at Jan 10, 2013, 03:49 AM

                  I would have thought an actual announcement of the release by MODX central would be appropriate, really. I only came to realize that 1.0.8 existed through Twitter. I'd expect to see it here first, but had to dig around to find anything about it. Nothing in Announcements or Security Notices, nor in sites' Security Notices feed.

                  I received security notice via Feedburner yesterday. It's also listed in Security Notices: https://forums.modx.com/thread/81545/modx-evolution-1-0-7-and-prior-forgotmanager-plugin-vulnerability

                  But the new 1.0.8 version is missing from Evo Discussion & Support board though: https://forums.modx.com/board/48/evo-discussions-support
                    Mikko Lammi, Owner at Maagit
                    • 9995
                    • 1,613 Posts
                    We had the same hack on a site. wp-conf.php , formajax.php and some more files where in different maps. It sends spam with -> LOL check this party pics facebook.asdasd.ru/virus.zip

                    The weird thing about it is this weekend we had the hack on a site which had ForgotManagerPassword set off.

                    We found out this hack because of the outgoing email limit message.

                    #EDIT#

                    I thought it had to be an other plugin which was causing a leak, seemed it was forgotmanager afterall.. I disabled it and still got hacked, but re-checking log files the hack was before I disabled it.

                    [ed. note: fourroses666 last edited this post 13 years, 8 months ago.]
                      Evolution user, I like the back-end speed and simplicity smiley
                      • 37550 ☆ A M B ☆
                      • 711 Posts
                      Hi,

                      Thanks for the reply that's interesting to hear and I will keep my eye out on these domains to see if it occurs again, we also only detected it via the email limits on the server.

                      Thanks Aaron
                        http://www.onesmarthost.co.uk
                        UK MODX Hosting with love.