We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 40359
    • 25 Posts
    Hello, maybe this is stupid question, but how safe MODX is from hacking. I know that there are lot hacking tools for Joomla and WordPress,is there something similar for MODX. I don't want to hack someone web site, just to make sure that someone don't hack my site, because I want to make web site with sort of user confidential data, and wouldn't like someone to get access to it, even users that can sign in as front end users with permissions to create and modify resources, but with no access to manager...
      • 40359
      • 25 Posts
      Generally, the user will be logged in as a web user and a manager.
      He will only have access to one resource and can update it with ajax snippet.
      Everything will be stored in content with imploded array.

      Something like this:

      $doc = $modx->getObject('modResource', $_GET['id']);
      $doc->set('content', $_GET['data']);
      $doc->save();


      How secure is that?
        • 28042 ☆ A M B ☆
        • 24,524 Posts
        Can a user belonging to that group access the Manager?

        You are not validating those GET values. Anybody can send a URL with anything they want in that GET.
          Studying MODX in the desert - http://sottwell.com
          Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
          Join the Slack Community - http://modx.org
          • 3749
          • 24,544 Posts
          Would NewsPublisher meet your needs? Using it to let users update their resource would avoid letting them into the Manager at all. It would also protect you from a variety of attacks that your method is open to.
            Did I help you? Buy me a beer
            Get my Book: MODX:The Official Guide
            MODX info for everyone: http://bobsguides.com/modx.html
            My MODX Extras
            Bob's Guides is now hosted at A2 MODX Hosting
            • 40359
            • 25 Posts
            User can't access to the manager dashboard. I will put some more checking in snippet, like is user logged in, so i don't think that anybody can POST with URL... :/

            I would like that everything of this going with ajax, and I will use ajax file upload, so I'm not sure can NewsPublisher be used for this...
              • 3749
              • 24,544 Posts
              To log in, the user group needs a Context Access ACL entry with a context of 'mgr'.

              To see any resources in the web context in the tree, the user group needs a Context Access ACL entry with a context of 'web'.

              What they can do and see in the Manager is determined by the permissions checked in the policy attached to the first of the above. I'd start by checking them all, then clearing permissions and sessions on the Security menu.

              If that doesn't solve your problem, something else is going on. If it does, you can start unchecking the permissions a few at a time to determine which are really necessary.

                Did I help you? Buy me a beer
                Get my Book: MODX:The Official Guide
                MODX info for everyone: http://bobsguides.com/modx.html
                My MODX Extras
                Bob's Guides is now hosted at A2 MODX Hosting
                • 40359
                • 25 Posts
                I unchecked something in permissions, they cant see manager dashboard even if they are logged in to manager and can create resources.

                We are little of the subject, I just wanted to know how safe it is generally, but I guess I make it weaker with every permission for logged in users. Anyway, they hack in to FBI and NASA website, nothing can't stop them if they are really up to me. smiley
                  • 28042 ☆ A M B ☆
                  • 24,524 Posts
                  The majority of the "big" hacks are done by getting passwords through social engineering (a phone call from "support" needing your password...a test found that more than half of several companies' users would be willing to give up their logins for gifts!). If your passwords are secure, and your computer doesn't have any keyloggers or other "viruses" you'll be fine. If you are on a shared hosting plan, then your site can only be as secure as their servers. If their server passwords get compromised, then nobody on the server is safe.

                  Rule #1: Never use "admin" or your own name as a username - after all, the username is half of your login! I have a link to a password-generating tool on my browser's toolbar, http://strongpasswordgenerator.com/, and it can be used for both usernames and passwords.

                  Rule #2: Never have an "option" you don't need, or a script that you don't use hanging around on the server. One of the earlier vulnerabilities on MODx 1.x was .php files for the code used in snippets - it was fairly standard to have the actual snippet code in a file like "ajaxsearch.snippet.php" in the assets/snippets/snippetname/ directory. A more recent issue involved the "forgot password" link on the Manager login form. None of my sites were vulnerable to that because I always removed that link from my Manager login forms; now I just disallow the feature in the System Settings.
                    Studying MODX in the desert - http://sottwell.com
                    Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                    Join the Slack Community - http://modx.org