-
☆ A M B ☆
- 711 Posts
Hi,
I thought I would share this with you all and for anyone that continues to run an old version of Evolution, this morning we have detected that a few of our customer sites who are running MODx old versions of MODx Evolution < 1.0.7 have had their site hacked through the exploits in the previous versions which has resulted in a lot of spam trying to go through our servers.
I would highly recommend to those that have not got round to upgrading to do so straight away we have had several sites affected so far and are now working with customers to make sure they upgrade to the latest version straight away.
Also the infected files being injected into the site are called wp-conf.php so it may be worthwhile checking your site for theses files if you run an old version also.
Hope that helps
Aaron
Do you know how they do it? Was it the Forgot Manager Login?
-
☆ A M B ☆
- 711 Posts
Hi Cipa,
I have just checked through our logs and can confirm it was via the Forgot Manager Login, the hacker was also quite quick with a couple of calls to that they then had access to the website and also placed on the website a file called formajax.php.
Thanks Aaron
Were the injected files in the MODX root?
-
☆ A M B ☆
- 711 Posts
Hi Bob
They were a little scattered
domainname.com\wp-conf.php
domainname.com\wwwroot\wp-conf.php
Then there were some random file names, and also a lot of new index.php files in sub folders like assets.
So far since the weekend we seem to be in good shape, disabling the forgot manager plugin and upgrading sites may have helped there.
We are also migrating to new Windows 2008 servers which will have some improved security to stop the PHP process writing to certain folders however a hacker could still exploit a site if its out of date and inject the file into the writeable cache folder.
Aaron
It is worth to be mentioned that Evolution 1.0.8 is out since yesterday.
May be someone adds a 1.0.8 subforum to the Evo forum?
We had the same hack on a site. wp-conf.php , formajax.php and some more files where in different maps. It sends spam with -> LOL check this party pics facebook.asdasd.ru/virus.zip
The weird thing about it is this weekend we had the hack on a site which had ForgotManagerPassword set off.
We found out this hack because of the outgoing email limit message.
#EDIT#
I thought it had to be an other plugin which was causing a leak, seemed it was forgotmanager afterall.. I disabled it and still got hacked, but re-checking log files the hack was before I disabled it.
[ed. note: fourroses666 last edited this post 13 years, 8 months ago.]
Evolution user, I like the back-end speed and simplicity

-
☆ A M B ☆
- 711 Posts
Hi,
Thanks for the reply that's interesting to hear and I will keep my eye out on these domains to see if it occurs again, we also only detected it via the email limits on the server.
Thanks Aaron