-
☆ A M B ☆
- 24,524 Posts
Probably not in the database, most likely in the index.php file, or possibly the config.inc.php file. Check your user list for a suspicious-looking user name, and change the usernames and passwords for all of your Manager users.
There also may be some odd .php files; you can look at the dates on the files and usually see the ones that are newer than all of the others if they are suspicious. Also check the modified dates on the files, to see if any other MODX files have been changed.
-
☆ A M B ☆
- 24,524 Posts
Well, that's your problem.
https://forums.modx.com/thread/89564/warning-hacking-attack-on-revo-2-2-4-using-core-services-plugin
Recommended to read the whole thread, there appear to be some files involved as well as the bogus plugin and user.
Solution was to delete the bogus "core-services" plugin. Changed user passwords etc, upgraded. And all seems okay now.