We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 30269
    • 119 Posts
    This morning we found that our Revolution 2.2.2pl install was hacked. The hackers uploaded many malicious php files in the root folder, the /assets, /assets/images and /engine. We are hosting multiple websites and through the exploit they managed to also infect other virtual hosts.

    We do not know how the hackers came in. All we found was this: http://bot24.blogspot.com/2013/01/new-vulnerabilities-in-modx-revolution.html information. But really, at this point all we do is wild-guessing, so this link might be useless for our problem??

    Today we installed latest version and prey the bug was fixed.

    Any ideas? [ed. note: Tom last edited this post 13 years, 7 months ago.]
      • 30269
      • 119 Posts
      Strange.. no one got any idea? Or did I post this on wrong place?
        • 37099
        • 338 Posts
        Maybe it's a vulnerability in the hosting rather than MODX ?

        Or other software on the same host?
          • 30269
          • 119 Posts
          Thanks for the answer.
          Given the sort of breach and the way they are targetting certain url's we are like 99% sure it was MODX and someone with strong MODX knowledge.

          We have No other software on host. It is a secure as possible latest linux distro.
            • 37099
            • 338 Posts
            That is disturbing. I hope the MODX team can find time to look into it.

            Have you had any problems since you upgraded to the latest version?
              • 30269
              • 119 Posts
              Quote from: thingstodo at Feb 04, 2013, 04:47 PM

              Have you had any problems since you upgraded to the latest version?
              Not as we speak off. We are hardening our site now... but still, it should not have been possible in the first place...
                • 9207 ☆ A M B ☆
                • 2,475 Posts
                It is extremely difficult to pinpoint hacking vectors, and most of the time clients/owners are more interested in getting the site back online ASAP rather than "preserving the crime scene for further investigation."

                Here are a couple ways a hacker might gain access to your site:

                1. One of your users re-used the same password, so another site was hacked and their password cracked from the other site, and somehow the hacker eventually tried logging into this MODX site. Even a user with limited permissions could upload a file that could be used to help gain FTP access.
                2. Weak FTP passwords (see also #1). This one is bad because it can lead to total ownage.
                3. Weak server. If a port scan / banner-grab reveals any unpatched technology on the server hosting the site, it only takes a hacker a few minutes to load up an exploit and get root on your server.
                4. Vulnerabilities in the code: if there were vulnerabilities in the MODX code or in any 3rd party code running on the site, that can be a way to gain control of a site (e.g. running older, unpatched versions of any CMS or any plugin can be dangerous).

                That list is by no means exhaustive, it's just a place to start...
                  • 22303 MODX Staff
                  • 10,725 Posts
                  Tom, if you can find in your access logs any potential attacks (look for POST requests around the time the file was created), and identify what URI within the MODX site was used to upload the malicious file, that will go a long way in determining the vector of the attack. Look particularly at POSTs to any forms on your site where user information is provided...
                    • 30269
                    • 119 Posts
                    @Everette: thanks for ideas:
                    1 - we never use FTP... only SSH. FTP servers are no-go on any of our servers
                    2 - hence no FTP password. SSH passwords are randomized, 16 character minimal
                    3 -servers are fully up to date every day.... we are now seeing what we can to limit port scans, rootkits and so on. But.... hacker did not get into server as far as we can tell. They stayed soley in www-data folders
                    4 - yeah.. .that must be it.... but... where ... ?

                    @Opengeek:
                    We are going through every detail in log file today and report here on our findings. Good tip of course to compare malicious file stamp with log entry. Sometimes we forget details in such a crazy period.

                    Thanks guys, we will be back here.
                      • 9207 ☆ A M B ☆
                      • 2,475 Posts
                      Spelling police: Everett without an e.

                      1. If someone re-used a password, what would they be able to do in the manager?

                      2. If you've got FTP disabled, then consider disabling password logins entirely and rely on SSH keys. They are practically impossible to brute-force hack.

                      3. You should definitely limit port scans. If a stranger is port-scanning you, you should block that IP in a heartbeat. That won't prevent them from completing a port scan, but it will make it much more difficult and much slower to
                      complete.

                      hacker did not get into server as far as we can tell.


                      That's the maddening thing about hacks: are you willing to wager on that? A good hack is one that doesn't get caught and simply lurks unnoticed.

                      4. Take note of every version of software you were running at the time of the hack, including MODX and any add-ons. If there are known vulnerabilities in any of those versions, then you can search for potential exploits in those versions. exploit-db.com is a one-stop shop for hackers looking to get into a system. It's more likely, however, that it was an automated hack of some sort (your logs probably show that).

                      There's always the possibility of a zero-day hack: i.e. some clever hacker figured out a new and novel way to abuse the code. Those are scary possibilities, which is why some companies like Google and Apple offer cash rewards for anyone who turns one in.

                      Hope that helps -- I would guess #4 is the most probable vector. Your sysadmins should be able to help figure out some of the puzzle pieces. You can read a blog post I wrote recently about this if it's helpful: http://tipsfor.us/2013/01/14/help-my-site-was-hacked/ [ed. note: Everettg_99 last edited this post 13 years, 7 months ago.]