Spelling police: Everett without an e.
1. If someone re-used a password, what would they be able to do in the manager?
2. If you've got FTP disabled, then consider disabling password logins entirely and rely on SSH keys. They are practically impossible to brute-force hack.
3. You should definitely limit port scans. If a stranger is port-scanning you, you should block that IP in a heartbeat. That won't prevent them from completing a port scan, but it will make it much more difficult and much slower to
complete.
hacker did not get into server as far as we can tell.
That's the maddening thing about hacks: are you willing to wager on that? A good hack is one that doesn't get caught and simply lurks unnoticed.
4. Take note of every version of software you were running at the time of the hack, including MODX and any add-ons. If there are known vulnerabilities in any of those versions, then you can search for potential exploits in those versions. exploit-db.com is a one-stop shop for hackers looking to get into a system. It's more likely, however, that it was an automated hack of some sort (your logs probably show that).
There's always the possibility of a zero-day hack: i.e. some clever hacker figured out a new and novel way to abuse the code. Those are scary possibilities, which is why some companies like Google and Apple offer cash rewards for anyone who turns one in.
Hope that helps -- I would guess #4 is the most probable vector. Your sysadmins should be able to help figure out some of the puzzle pieces. You can read a blog post I wrote recently about this if it's helpful:
http://tipsfor.us/2013/01/14/help-my-site-was-hacked/
[ed. note: Everettg_99 last edited this post 13 years, 7 months ago.]