We checked the log files yesterday. The hackers were smart enough to continously overwrite and rename their own files, so the time stamps got lost quickly and searching on the file names let to nothing. But, after old fashoined hand labour on 700.000 log lines we found the cause.
To our shame, the leak was found not in MODX Revolution as stated above... but in MODX Evolution 1.0.5. This Evolution code should have been removed long ago... but was orphaned after the big upgrade we had to do when we went from 1.0 to 2.0.
What happened?
It was a simple SQL-injection which provided access to admin panel by user with name 'admin' (default username for administrator on MODx): manager/processors/login.processor.php? .... (more in PM if you are interested) With access to the administration panel they have uploaded their php-script to a folder with public access (/assets/images), and then later a some bots began sending a various POST requests and being uploaded other scripts and files to infect other folders and hosts.some of these script used as a sender of different spam-messages by email, another one as a proxy-script, another one as redirection script which redirects to different sites to increase their page rank. Probably it's handiwork of Russian or Russian-speaking hackers.
Lesson learned? - Never use "admin" as the username of admin ... but we knew that long ago, of course....
PS- The title of this post is wrong. We are happy to not have found any Revo Exploit !!
[ed. note: Tom last edited this post 13 years, 7 months ago.]
-
☆ A M B ☆
- 24,524 Posts
You can edit your post and change the title, as well as marking it Answered.
Hi Tom,
very interesting. For not doing the same mistake can you just tell how they got the password of the admin? And which code did they use to do the injection?
@gemand. Yes, MODX core devs are in the loop, so they can see if fix is needed.