Hello,
I am brand new to modx: My company has inherited a modx-based site that may have been compromised by the blackhole exploit kit.
My first instinct is to see if the code installed on the site matches the release version from github. However, I don't know yet the file layouts to determine what files are added as a result of use, what might be a plugin, and what might be code.
manager/includes/version.inc.php shows the version of the site to be 1.0.5 "evolution" so I hope I have posted this in the correct location...
Thank you in advance for your time...
--jason
Generally, the files in the manager/ directory won't change with use.
The most likely files to be altered in an attack are the index.php files in the root and manager directories, and the .htaccess file in the root, though some exploits only alter the assets/cache directory, which makes them hard to detect because that changes all the time.
If the site has been breached, the attacker may now have your username and password for MODX, cPanel, FTP, and/or the DB.
The best solution is to change all passwords and usernames, wipe the site and restore from a pre-breach backup (assuming that you have one).
Hello,
Thanks for replying! I appreciate it!
Actually that brings up a question: will modx ever modify its own .htaccess files?
--jason
It doesn't at present, though I imagine that there could be a future version in which turning on FURLs and www/non-www rewriting in the Manager would lead to an automatic .htaccess rewrite.
-
☆ A M B ☆
- 24,524 Posts
Considering that the MODx site itself is served using an nginx web server, I don't see it happening any time soon. There are too many web servers with different configuration methods. Anyway, having a "." file (a system file) edited automatically by a web application is definitely not something to be encouraged, as any system admin would tell you.