We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 38713
    • 91 Posts
    Our hosting provider sent us an email to bring attention to the fact a malicious file had been uploaded to our modx installation.

    The following was stated:

    Our internal monitoring picked up a malicious file upload to your webspace machines.edmplus.co . It was uploaded to connectors/security/settings/php and is a PHP command shell script.

    Unfortunately I've been unable to ascertain exactly how this file was uploaded (but have confirmed from our disaster recovery backups that it definitely is a newly uploaded file).

    I have since removed the file as php command shells are not allowed on our hosting, but I wondered if you had any insight as to how this file appeared in your hosting? The timestamps indicate the file appeared at around 17:15pm yesterday but its possible these are misleading and it appeared earlier (but no earlier than 1am yesterday morning).

    We then had a further email once they had done a bit more digging which went on to explain:

    I took a further look and have found the access logs that show when the file was uploaded :

    77.120.108.186 - - [05/Mar/2014:17:15:41 +0000] "POST /connectors/resource/index.php HTTP/1.0" 401 442 "-" "-"
    77.120.108.186 - - [05/Mar/2014:17:15:41 +0000] "POST /connectors/resource/index.php HTTP/1.0" 200 382 "-" "-"
    77.120.108.186 - - [05/Mar/2014:17:15:42 +0000] "POST /connectors/resource/index.php HTTP/1.0" 401 335 "-" "-"
    77.120.108.186 - - [05/Mar/2014:17:15:43 +0000] "POST /connectors/resource/index.php HTTP/1.0" 401 335 "-" "-"
    77.120.108.186 - - [05/Mar/2014:17:15:43 +0000] "POST /connectors/resource/index.php HTTP/1.0" 401 335 "-" "-"
    77.120.108.186 - - [05/Mar/2014:17:15:43 +0000] "POST /connectors/resource/index.php HTTP/1.0" 200 382 "-" "-"
    77.120.108.186 - - [05/Mar/2014:17:15:44 +0000] "POST /connectors/security/login.php HTTP/1.0" 200 547 "-" "-"
    77.120.108.186 - - [05/Mar/2014:17:15:45 +0000] "POST /connectors/security/user.php HTTP/1.0" 200 998 "-" "-"
    77.120.108.186 - - [05/Mar/2014:17:15:47 +0000] "POST /connectors/browser/file.php HTTP/1.0" 200 469 "-" "-"

    These are all requests against machines.edmplus.co and it was the last request that resulted in the file being uploaded (see email below this one).

    I've checked your modx version and you're running 2.2.8, the currently latest version (released yesterday as it happens) is 2.2.13.

    From the changelog : https://raw.github.com/modxcms/revolution/v2.2.13-pl/core/docs/changelog.txt

    I cannot see any reference to an RFI vulnerability being fixed since 2.2.8, and I can find no reference to one via Google, which doesn't mean there isn't one, it may mean this is a 0day.

    We were running 2.2.8 at the point of the attack as you can see above, but have upgraded it to 2.2.13 now.

    Anyone have any thoughts?

    Thanks
      Twitter @alexmercenary
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      Looks like somebody has access to your Manager. That connector gives access to the Manager's file browser.
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 38713
        • 91 Posts
        Ah what! Don't say that Susan! Not what I wanted to hear.
          Twitter @alexmercenary
          • 38713
          • 91 Posts
          And I can confirm you are right. I have the following user in my users table

          username: connectorsAdmin
          email: f***youmodxrevolutionagain2@asdasd`.`ru
          user class key: modUser

          the f*** isnt actual asterisks but a word that rhymes with duck.
            Twitter @alexmercenary
            • 28042 ☆ A M B ☆
            • 24,524 Posts
            Make sure you're updated, change all of your usernames/passwords (don't use something like "admin" for a username), and make sure you don't have any keylogging or sniffing malware on your computer.

            Easy update... use the new installer script
            https://github.com/evolution-cms/installer
            https://forums.modx.com/thread/89455/modx-installer---to-install-any-version-of-modx-quickly#dis-post-492059
              Studying MODX in the desert - http://sottwell.com
              Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
              Join the Slack Community - http://modx.org
              • 38713
              • 91 Posts
              Ah nice! That's a cool script. I'm definitely gonna have a tinker with that.

              Yea ill have to check various computers for keyloggers I guess. Still it's very odd. I have a lot of MODX sites which I manage from this computer and am yet to experience this issue on any other site I have ever done.

              Maybe it's the clients PC. I'll have to dig around.

              Interesting.
                Twitter @alexmercenary
                • 27708 MODX Staff
                • 2,502 Posts
                We're going to look at it on our and to see if there are any vulnerabilities that could enable this user registration. Not sure if this was possible via phpThumb or not.
                  Author of zero books. Formerly of many strange things. Pairs well with meats. Conversations are magical experiences. He's dangerous around code but a markup magician. Blog ✦ Twitter ✦ LinkedIn ✦ GitHub
                  • 38713
                  • 91 Posts
                  Rightie dokie. I shall eagerly await your response
                    Twitter @alexmercenary
                    • 18373 ☆ A M B ☆
                    • 3,141 Posts
                    Perhaps the SQL injection fixed in 2.2.13 was used to create the manager login?
                      Mark Hamstra • Developer spending his days working on Premium Extras and a MODX Site Dashboard with the ability to remotely upgrade MODX and extras to make the MODX world a little better.

                      Tweet me @mark_hamstra, check my infrequent blog at markhamstra.com, my slightly more frequent ramblings at MODX.today or see code at Github.
                      • 40737
                      • 32 Posts
                      I think the pdo sql injection was used here because the same email address for this new user is used in the exploit i found at github.

                      Best,

                      Mike