We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 22303 MODX Staff
    • 10,725 Posts
    Quote from: doggystyle at Mar 10, 2014, 07:56 AM
    I think the pdo sql injection was used here because the same email address for this new user is used in the exploit i found at github.
    What exploit found at github are you referring to?
      • 40737
      • 32 Posts
      I did send you a PM
        • 44234
        • 219 Posts
        Quote from: markh at Mar 10, 2014, 07:55 AM
        Perhaps the SQL injection fixed in 2.2.13 was used to create the manager login?

        I've seen that email address used in articles referencing the exploit patched in 2.2.13
          Find me on Twitter, GitHub or Google+
          • 35150 ☆ A M B ☆
          • 191 Posts
          Quote from: davidpede at Mar 10, 2014, 10:57 AM
          I've seen that email address used in articles referencing the exploit patched in 2.2.13

          It comes from a blog post on Agel Nash's site. He partially illustrates a SQL injection and a security hole involving switching contexts. The latter was closed in 2.2.13, but the SQL injection still works.
            Extras :: pThumb • Resizer • imageSlim • setPlaceholders
            • 24629
            • 370 Posts
            You're saying the SQL injection still works in 2.2.13 ?? can we expect a 2.2.14 soon?

            RDG
              • 22303 MODX Staff
              • 10,725 Posts
              The SQL injection is patched in 2.2.13.
                • 35150 ☆ A M B ☆
                • 191 Posts
                Quote from: rdaneeel at Mar 10, 2014, 02:23 PM
                You're saying the SQL injection still works in 2.2.13 ??

                That's what Agel Nash says at least. I haven't tried it and don't know. Opengeek ought to know best smiley

                Here's a rough translation of the end of the aforementioned blog post:
                Update 03/08/2014

                Version 2.2.13 is out and it should fix the hole which allows unauthorized entry to a site via contexts. But the SQL injection while getting objects trick still works. I guess they consider this less critical and decided a fix can wait till the 2.3 release. In general I recommend everybody update...
                  Extras :: pThumb • Resizer • imageSlim • setPlaceholders
                  • 612 ☆ A M B ☆
                  • 9 Posts
                  Quote from: jgrant at Mar 10, 2014, 04:10 PM
                  Version 2.2.13 is out and it should fix the hole which allows unauthorized entry to a site via contexts. But the SQL injection while getting objects trick still works. I guess they consider this less critical and decided a fix can wait till the 2.3 release. In general I recommend everybody update...

                  Here there was confusion over the terms due to the release 2.2.13 also closing SQL-injection. In the article on my blog I showed the ability to perform queries with context initialization.

                  Version 2.2.13 also had a problem with SQL-injection. And both vulnerability and closed one patch. But this patch covers only door in the core/connectors. And then there are doors and third-party applications (components).

                  I think you just need to be patient and wait for the next version MODX Revolution.
                  And about the exploit on GitHub - this demo (not working). Could only be used as a prototype for someone :-(

                  Sorry for my english
                    Security Expert
                    • 37242 ☆ A M B ☆
                    • 339 Posts
                    I found that I have the same file (settings.php) and the same user in a clients installation. It's also MODX 2.2.8.

                    From the Manager log:

                    Wed Mar 05, 2014 06:03 PM

                    connectorsAdmin

                    file_create

                    /is/htdocs/12345..***/www/connectors/security/settings.php
                      • 25803 ☆ A M B ☆
                      • 721 Posts
                      We have a file called list.php in connectors/security/list.php which is a trojan, also using 2.2.8. Does an upgrade kill the trojan or is there more to be done?