-
☆ A M B ☆
- 24,524 Posts
Looks like somebody has access to your Manager. That connector gives access to the Manager's file browser.
Ah what! Don't say that Susan! Not what I wanted to hear.
Twitter @alexmercenary
And I can confirm you are right. I have the following user in my users table
username: connectorsAdmin
email: f***youmodxrevolutionagain2@asdasd`.`ru
user class key: modUser
the f*** isnt actual asterisks but a word that rhymes with duck.
Twitter @alexmercenary
-
☆ A M B ☆
- 24,524 Posts
Make sure you're updated, change all of your usernames/passwords (don't use something like "admin" for a username), and make sure you don't have any keylogging or sniffing malware on your computer.
Easy update... use the new installer script
https://github.com/evolution-cms/installer
https://forums.modx.com/thread/89455/modx-installer---to-install-any-version-of-modx-quickly#dis-post-492059
Ah nice! That's a cool script. I'm definitely gonna have a tinker with that.
Yea ill have to check various computers for keyloggers I guess. Still it's very odd. I have a lot of MODX sites which I manage from this computer and am yet to experience this issue on any other site I have ever done.
Maybe it's the clients PC. I'll have to dig around.
Interesting.
Twitter @alexmercenary
-
MODX Staff
- 2,502 Posts
We're going to look at it on our and to see if there are any vulnerabilities that could enable this user registration. Not sure if this was possible via phpThumb or not.
Author of zero books. Formerly of many strange things. Pairs well with meats. Conversations are magical experiences. He's dangerous around code but a markup
magician.
Blog ✦
Twitter ✦
LinkedIn ✦
GitHub
Rightie dokie. I shall eagerly await your response
Twitter @alexmercenary
-
☆ A M B ☆
- 3,141 Posts
Perhaps the SQL injection fixed in 2.2.13 was used to create the manager login?
I think the pdo sql injection was used here because the same email address for this new user is used in the exploit i found at github.
Best,
Mike