We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 40122
    • 330 Posts
    I recently set up a new site with Revo 2.1.3 (company refuses to upgrade VPS so this is the most latest version I can use) and got an email from the VPS saying:

    Recently Uploaded CGI scripts that send email on host.myvps.net
    
    Below are the recently upload scripts that contain code to send email.  You may wish to inspect them to ensure they are not sending out SPAM.
    


    With a bunch of lines like:

    /home/studio/public_html/newsite/core/model/modx/mail/phpmailer/class.phpmailer.php:128:    */
    /home/studio/public_html/newsite/core/model/modx/mail/phpmailer/class.phpmailer.php:129:   public $Sendmail          = '/usr/sbin/sendmail';
    /home/studio/public_html/newsite/core/model/modx/mail/phpmailer/class.phpmailer.php:130:


    I've not recieved an email like this before and do not know what the code means.

    Would anyone know what this means and if I should do anything about it?

    Many thanks

    This question has been answered by BobRay. See the first response.

    • discuss.answer
      • 3749
      • 24,544 Posts
      Please don't double post.

      Those are legitimate MODX files, so there's nothing to worry about. The host is just notifying you of uploaded files that send mail as a courtesy so if someone who has hacked your site uploads mail software you'll know about it.

      BTW, the company should really consider updating the server. Several security issues have been fixed since 2.1.3.
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 40122
        • 330 Posts
        Quote from: BobRay at Feb 13, 2014, 10:01 PM
        Please don't double post.

        Those are legitimate MODX files, so there's nothing to worry about. The host is just notifying you of uploaded files that send mail as a courtesy so if someone who has hacked your site uploads mail software you'll know about it.

        BTW, the company should really consider updating the server. Several security issues have been fixed since 2.1.3.

        Thanks!

        Yeah I totally agree! I am wasting a lot of time dealing with issues on these old sites. I am almost at the point where I suggest clients host with someone else!
          • 28042 ☆ A M B ☆
          • 24,524 Posts
          It looks like just a security warning, to let the server admin know that somebody uploaded a script capable of sending email. Since you know that you uploaded MODX, which does indeed include the phpmailer class, it's OK.

          However, that version of MODX includes a version of phpmailer that's known to be insecure, besides the security issues that older version of MODX itself has. You might want to take this very seriously, as they could hold you responsible for any security breaches they have.
            Studying MODX in the desert - http://sottwell.com
            Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
            Join the Slack Community - http://modx.org
            • 3749
            • 24,544 Posts
            Yeah I totally agree! I am wasting a lot of time dealing with issues on these old sites. I am almost at the point where I suggest clients host with someone else!

            http://bobsguides.com/modx-friendly-hosts.html wink
              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting