We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 36671 ☆ A M B ☆
    • 120 Posts
    Just checking if this happened to anybody else and for this to be a warning to others who have not yet upgraded their Evo sites to 1.0.10.

    Have to admit that I still had a couple of older Evo sites hanging around that had not yet been upgraded to 1.0.10 for a variety of reasons. The week before last, I suddenly got notification from my hosting provider that 2 of these sites got hacked. In both cases, an infected PHP file was dropped into the assets/cache folder and the host shut down my sites. I was able to restore both sites quite easily as these were the only infected files.

    However, the following day I received the below email:

    From: Evan Reed <[email protected]>

    Carolin

    MODx is an excellent way to publish your content on the World Wide Web, and with such a great resource there are bound to be attacks on it. This is where CodeGuard comes in! Did you know that every 0.6 seconds a website is hacked? This may seem daunting, but with a service like CodeGuard you can finally relax. CodeGuard backs up your files and databases and enables websites to be changed back to any previous backup if anything where ever to get hacked. Plain and simple, it is a time machine for your website! Never worry about the safety of your website again and start using CodeGuard today with a 14 day free trial!

    If you have any questions feel free to email or give us a call.

    Thanks,
    Evan

    --
    https://codeguard.com/
    1-866-604-6431 (US)
    Atlanta, GA, USA



    I know that codeguard.com is a reputable service but the email came from a gmail account and the link is to a https page. A bit odd I think and what a coincidence to come right after I get hacked!! Another site got hacked a couple of days later with the same symptoms. So I'm wondering if anybody else has has the same experience?

    Have upgraded all Evo sites to 1.0.10 now but just throwing this out there in case it's not an isolated case.

      • 41185 ☆ A M B ☆
      • 23 Posts
      Received similar email but site was not hacked. I just ignored the email.
        Developing Themes/Templates for MODx Revo. Visit http://mdxthemes.com
        • 22840
        • 1,572 Posts
        Not received the email but I do use codeguard and can honestly say it's an excellent service, not only is it a external backup but they email you after every backup to tell you if / what files have been changed which is excellent.
          • 36671 ☆ A M B ☆
          • 120 Posts
          Quote from: paulp at Jul 17, 2013, 03:59 AM
          Not received the email but I do use codeguard and can honestly say it's an excellent service, not only is it a external backup but they email you after every backup to tell you if / what files have been changed which is excellent.

          I agree that Code Guard is a reputable service. However, the email came from a gmail account which is a bit unusual ... can't tell what the link at the bottom of the email actually links to but not willing to try it out ...
            • 13226
            • 953 Posts
            I still wonder over things like this

            Open Source = anyone and everyone who wants to harm for one reason or the other, has the ultimate opportunity to work through all of the source code and find possible coding flaws, which if found, could in turn possibly lead to a successful hack.

            I have written about this before and will probably do it again.

            A couple of my popular sites have been previously hacked and as they say, once burnt twice shy.

            My advice to anyone that uses Open Source:

            1. Don't tell the world you are using an open source system e.g. don't publish it on your website
            2. If you use an Open Source product for your clients, don't put them at risk by adding them to your portfolio without asking prior permission
            3. Remove any obvious code that is typical of the system you are using - this type of code is a typical point of search for bots on the look out for specific systems e.g. powered by "NAME" cms
            4. Where possible block / password protect the Admin / Manager interface
            5. MODx specific - Delete or disable where possible all unused plugins, modules and snippets from the Admin / Manager interface
            6. MODx specific - Remove all unused plugin, module and snippet files from the assets folder
            7. Backup your website and database on a regular basis - but don't override old backups (just in case a hack took place before you realised it and you have backed the hack up with the last DB/Site backup)
            8. Keep a fully "up to date" working copy of your website on your computer = localhost (EasyPHP, Wamp, Zend Server CE, XAMPP etc.)

            If, lets say, one of the default snippets has a flaw and you don't actually use it, but you leave it as is, you are vulnerable to a hack

            A great example was not so long ago, the "Forgot Manager Login" plugin in Evo - I personaly have never used it, nor have my clients, so I never install it. My sites were not affected by this hack, simply because the code wasn't on the server or in the DB.

            Simple rule of thumb - get rid of what's not used, it limits the risk of being hacked.

            The best place to look for people who are using Open Source - The projects Forum, a small suggestion - don't add your website to your public profile, and don't use your real or company name. [ed. note: iusemodx last edited this post 13 years, 2 months ago.]
              • 28042 ☆ A M B ☆
              • 24,524 Posts
              This type of "security by obscurity" won't work. There are too many 'bot scripts being run against arbitrary websites looking for "signature" pages and files for any number of applications. One site I'm working on recently got hammered by a 'bot looking for specific .asp.net files and URLs related to some CMS or another. It was also looking for certain files associated with TinyMCE. I've seen some sites scanned for certain vulnerable phpThumb files. So if somebody is looking for MODx sites to hack, that's what will happen. In fact, newer 'bot scripts are programmed to scan for files and pages from several applications during the same attack. Any successful accesses are logged by the 'bot, and the 'bot manager then knows where to go for the real attack.
                Studying MODX in the desert - http://sottwell.com
                Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                Join the Slack Community - http://modx.org
                • 13226
                • 953 Posts
                Quote from: sottwell at Jul 18, 2013, 05:00 AM
                This type of "security by obscurity" won't work.

                Simply saying that these steps don't work is wrong, they help

                Quote from: sottwell at Jul 18, 2013, 05:00 AM
                looking for "signature" pages and files for any number of applications. It was also looking for certain files associated with TinyMCE. I've seen some sites scanned for certain vulnerable phpThumb files

                Please see points: 3, 5 & 6 in my original post

                If someone wants to hack a site they will - no question

                Touch wood - My sites have not been hacked in the last 2 years, and two sites have 10,000+ unique visitors per day and are in a niche where hacks are prevalent.

                So, all I can say is - It works for me and my client sites, so why shouldn't it work for others ? [ed. note: iusemodx last edited this post 13 years, 2 months ago.]