We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 2762
    • 1,198 Posts
    Last night i've found suspicious url in the Apache Status for one of my Evo site:

    mydomainmame.com/viagra.html

    mydomainmame.com/cialis-pastilla.html

    following these url, there's a redirect to a "farmacy" store (edwebstock dot com ) sad

    :( the site was obviously hacked

    Evo has been updated to 1.08, over a month ago, when I moved the site to a new server.

    I suspect they used the Forgot Manager bug, because i've found a new admin user (named support - support@mydomain.com).

    Now i'm cleaning up:

    - deleted the new account
    - changed evo admin password
    - changed DB password
    - deleted all evo files and replaced/updated with a clean 1.0.9

    Any suggestions?
      Free MODx Graphic resources and Templates www.tattoocms.it
      -----------------------------------------------------

      MODx IT  www.modx.it
      -----------------------------------------------------

      bubuna.com - Web & Multimedia Design
      • 9995
      • 1,613 Posts
      really check all your files, even lower as root.
      when looking at dates of maps / files you could/might find the .php files everywhere.

      for manager you could upload the new manager map and rename/delete the old one so that map is clean for sure. (backup configinc.php file)
        Evolution user, I like the back-end speed and simplicity smiley
        • 2762
        • 1,198 Posts
        I've deleted all old evo files and contents on the server and replaced with clean 1.0.9 files.
        Reuploaded only images and theme folders (after a check of all files in both folders) and the maxigallery folder (clean from repository).

        Fortunately its a simple site with only default snippets and maxigallery.


        I've downloaded the hacked site before deleting and found six infected php files inside the assets/cache folder:
        1.data.php, 2.data.php, 3.data.php, 4.data.php, 6.data.php, 6.data.php
          Free MODx Graphic resources and Templates www.tattoocms.it
          -----------------------------------------------------

          MODx IT  www.modx.it
          -----------------------------------------------------

          bubuna.com - Web & Multimedia Design
          • 2762
          • 1,198 Posts
          update: very bad thing.. after all cleaning ..the site seems infected again.

          still redirect on all fakes (404) pages sad sad [ed. note: banzai last edited this post 13 years, 5 months ago.]
            Free MODx Graphic resources and Templates www.tattoocms.it
            -----------------------------------------------------

            MODx IT  www.modx.it
            -----------------------------------------------------

            bubuna.com - Web & Multimedia Design
            • 3749
            • 24,544 Posts
            It's a good idea to change your FTP and cPanel credentials too -- and in the case of a site that's been hacked, I'd change the usernames too.

            Also, give the details to your host so they can look for the same thing in other sites. It may be that the server itself has been compromised.
              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting
              • 13428 ☆ A M B ☆
              • 1,031 Posts
              First important thing to look for with all Hacks: What is the attacking vector? How/when do they get in? Best place to look for that would be the server access log.

              If they have got into the manager or into the database, not only files could be infected but plugin/snippet php code inside of MODX database, too.

              Maybe the attack and infection was long before they really do anything visible on the server.
                • 2762
                • 1,198 Posts
                Quote from: Jako at Apr 11, 2013, 05:13 AM

                Maybe the attack and infection was long before they really do anything visible on the server.

                I think so too. I am not sure that they used the Forgot Manager bug, because it was still already updated to 1.08.
                I changed servers recently, but probably the infection was already present, but not "active"

                The site has a few years and, although it was constantly updated, there were still some very old Modx snippets and plugins (drop menu, newslisting, flex searchform, quick edit..) in the resource/elements lists.

                Re-cleaned all files

                Deleted ALL snippets and plugins from the DB and reinstalled updated versions with evo 1.0.9 install.

                let's see if I solved
                  Free MODx Graphic resources and Templates www.tattoocms.it
                  -----------------------------------------------------

                  MODx IT  www.modx.it
                  -----------------------------------------------------

                  bubuna.com - Web & Multimedia Design