We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 45383
    • 7 Posts
    Is it possible for ModX vulnerability to compromise an apache instance? I have a client of mine who is running a very old version of ModX Evolution and repeatedly the site goes off. The system administrator found out that apache was hacked.

    Does it make sense for an existing vulnerability in ModX to compromise apache?

    Below is what I see when I list processes running as apache

    apache 18324 0.0 0.0 0 0 ? Z 13:39 0:00 [sh] <defunct>
    apache 18330 0.0 0.0 5384 2976 ? S 13:39 0:00 -bash
      • 39404
      • 175 Posts
      stalemate resolution associate Reply #2, 12 years, 10 months ago
      Hi rxraza,

      Anything installed on a server can represent a way in to a hacker. They are officially called "attack vectors". Over the years, various vulnerabilities are found for either MODX or PHP, etc.

      Most updates to either Evo or Revo include security fixes along with new features.

      MODX has a rss feed which you can see vulnerabilities found for each version, or alternatively, what security holes each update fixes:

      http://feeds.feedburner.com/modxsecurity

      Usually when a new release comes out, they suggest that you update, if for no other reason, for the sake of security.

      Hope this helps.

      Regards,
      Tom
        • 45383
        • 7 Posts
        Quote from: stalemate at Nov 10, 2013, 08:34 PM
        Hi rxraza,

        Anything installed on a server can represent a way in to a hacker. They are officially called "attack vectors". Over the years, various vulnerabilities are found for either MODX or PHP, etc.

        Most updates to either Evo or Revo include security fixes along with new features.

        MODX has a rss feed which you can see vulnerabilities found for each version, or alternatively, what security holes each update fixes:

        http://feeds.feedburner.com/modxsecurity

        Usually when a new release comes out, they suggest that you update, if for no other reason, for the sake of security.

        Hope this helps.

        Regards,
        Tom

        I bet this is some security vulnerability that has been exploited. Whereas I don't mind updating to the latest version of evolution but I would like to find out as to what is it in script(s) that is causing this. I would appreciate any suggestion(s) to investigate the part that is causing this.
          • 39404
          • 175 Posts
          stalemate resolution associate Reply #4, 12 years, 10 months ago
          Hi rxraza,

          There are a few things you can do. Once you know what version of Evo you have, look at the detailed notes on each of the updates and see what security holes were fixed. I don't know if they indicate what lines of code were to blame (whether it be PHP or MODX) but I'm sure there are forum posts associated with these items which may indicate the code responsible.

          Out of interest, how does knowing what in the scripts which caused the security hole help? Is it just out of curiosity?

          Regards,
          Tom
            • 45383
            • 7 Posts
            Thanks for the reply. Good suggestion that is what I am planning to do.

            Knowing what caused it would help understand how the attack got implanted. I have been monitoring processes running under apache user and so far below processes pop up at random intervals

            apache 18324 0.0 0.0 0 0 ? Z 13:39 0:00 [sh] <defunct>
            apache 18330 0.0 0.0 5384 2976 ? S 13:39 0:00 -bash

            I can update to the most recent available version of evolution but the mystery would remain about where the injection is coming from.

            [ed. note: rxraza last edited this post 12 years, 10 months ago.]
              • 28042 ☆ A M B ☆
              • 24,524 Posts
              If I recall correctly, the two main problems over the last few years have been redundant .php files representing snippet code (usually something like snippetname.snippet.php) which could be run from outside (domain.com/assets/snippsts/snippetname/snippetname.snippet.php), and a bug with the Manager "forgot password" system allowing hijacking of Manager users, which would allow the upload of scripts to the site's filesystem through the Manager's File Manager.
                Studying MODX in the desert - http://sottwell.com
                Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                Join the Slack Community - http://modx.org
                • 1343 ☆ A M B ☆
                • 2,213 Posts
                I'm not sure you are looking in the right place, while MODX is one possible attack vector, it sounds like the server was compromised/rooted. I can think of several questions I would be asking my hosting provider:

                • What version of Apache is in use, and was it vulnerable to any exploits that could explain the problem
                • Why wasn't this problem caught earlier
                • What steps have you taken to ensure our server is secure
                • Do you have any information on how they might have accessed the server
                • Did you check for any backdoors, if so what was the result?

                If the server was unmanaged you need to be talking to your server administrator, as you should have measure in place to prevent problems like this one. If the server was managed you need to be looking at how this went undetected, and evaluating if their management skills are to be trusted.

                Personally my first step would be securing a new server, locking it down, moving the site, and ensuring it's been locked down as well. I wouldn't trust a server that has been compromised at the service level.

                That being said depending on what version of MODX you had installed there are several attack vectors that could be used for initial access, and if the server wasn't secured used to elevate access to the server. The same can also be said for anything installed on your server, such as Apache exploit(s), Control Panel exploit(s) - If you have a control panel installed, insecure login permissions, etc.

                  Patrick | Server Wrangler
                  About Me: Website | Tweets |  MODX Hosting