We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 26503
    • 620 Posts
    I inherited a modx revo site that kept getting continually hacked, most recently a week or so ago so it got updated to 1.0.14 ~ problem seemed to go away.

    ~However~

    The previous developer had extended the moduser object [I guess] so that users had these extensive user profiles they could manage. Now when a user logs in, they get the wrong profile!

    I.e. user with an ID of 100 in the web users table will log in but they will get the profile for user 99 ~ if I check the sessions table, the user class key is for user 99 not 100.

    I have none experience with Evo and no idea where to start looking to figure this one out... [and yes it's always one record before it's like modx tries to log in (user_id -1) )

    -thanks
    -sean
      *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

      Sean Kimball CLP, CLS.
      Technical Director / Sr. Developer | BigBlock Studios
      ._______________________________________________.
      Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
      27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
      phone/fax: 905-426-5525
      • 20413
      • 2,877 Posts
      Extending the moduser object in Evo... is possible if the developer has configured xPDO for user management!?
      http://rtfm.modx.com/revolution/2.x/developing-in-modx/advanced-development/extending-moduser

      If the site got hacked - scan through all folders and look for files created the same date!!
      These files normally mimics file-names you expect to be where they are.

      They act as backdoors into your site and deletion is the only remedy.


      + Change all passwords Server, MODX, FTP and make sure there are no new users added(!)

      https://forums.modx.com/thread/91891/is-it-a-hack?page=2#dis-post-502182
      https://forums.modx.com/thread/85986/modx-revolution-2-2-6-hack-appearing-in-assets-folder?page=4#dis-post-502426

      [ed. note: mrhaw last edited this post 12 years, 2 months ago.]
        @hawproductions | http://mrhaw.com/

        Infograph: MODX Advanced Install in 7 steps:
        http://forums.modx.com/thread/96954/infograph-modx-advanced-install-in-7-steps

        Recap: Portland, OR (PDX) MODX CMS Meetup, Oct 6, 2015. US Bancorp Tower
        http://mrhaw.com/modx_portland_oregon_pdx_modx_cms_meetup_oct_2015_us_bancorp_tower
        • 26503
        • 620 Posts
        they had done so & it's worked for years, several extra tables in there with all the extra user data. Looks like a bang up job really.


        but I've been through the file cleaning process several times, it's always 0 day, the most recent vulnerability for evo gets released and a day later this site gets hacked. It's just on someone's radar is all. [though a giant pain in the ass!]


        I really don't think this has anything to do with the compromises, something in the way logins/user profiles are handled was changed...


        Quote from: mrhaw at Jul 03, 2014, 09:47 AM
        Extending the moduser object in Evo... is possible if the developer has configured xPDO for user management!?
        http://rtfm.modx.com/revolution/2.x/developing-in-modx/advanced-development/extending-moduser

        If the site got hacked - scan through all folders and look for files created the same date!!
        These files normally mimics file-names you expect to be where they are.

        They act as backdoors into your site and deletion is the only remedy.

        https://forums.modx.com/thread/91891/is-it-a-hack?page=2#dis-post-502182


          *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

          Sean Kimball CLP, CLS.
          Technical Director / Sr. Developer | BigBlock Studios
          ._______________________________________________.
          Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
          27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
          phone/fax: 905-426-5525
          • 20413
          • 2,877 Posts
          I would install the current updated site on a local server.
          Then from the old site's db just export the user tables and overwrite them on the new database.
            @hawproductions | http://mrhaw.com/

            Infograph: MODX Advanced Install in 7 steps:
            http://forums.modx.com/thread/96954/infograph-modx-advanced-install-in-7-steps

            Recap: Portland, OR (PDX) MODX CMS Meetup, Oct 6, 2015. US Bancorp Tower
            http://mrhaw.com/modx_portland_oregon_pdx_modx_cms_meetup_oct_2015_us_bancorp_tower
            • 26503
            • 620 Posts
            I'm not sure where you are going with that... how is copying over the data going to help?

            Quote from: mrhaw at Jul 03, 2014, 10:02 AM
            I would install the current updated site on a local server.
            Then from the old site's db just export the user tables and overwrite them on the new database.
              *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

              Sean Kimball CLP, CLS.
              Technical Director / Sr. Developer | BigBlock Studios
              ._______________________________________________.
              Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
              27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
              phone/fax: 905-426-5525
              • 20413
              • 2,877 Posts
              > I don't know... EVO has no session_table in the db. Is this setup connected to EVO's web user handling at all?

              > How did you do the upgrade? Did you clear cache before and after? Did you click to overwrite weblogin snippet and files?
              Can you get up the old site to compare with?

              > Can you get a hold of the previous developer for a dialouge?

              > In EVO web-users has a negative integer and mgr-users a positive...

              > Have you wiped the stored sessions on the server and locally.

                @hawproductions | http://mrhaw.com/

                Infograph: MODX Advanced Install in 7 steps:
                http://forums.modx.com/thread/96954/infograph-modx-advanced-install-in-7-steps

                Recap: Portland, OR (PDX) MODX CMS Meetup, Oct 6, 2015. US Bancorp Tower
                http://mrhaw.com/modx_portland_oregon_pdx_modx_cms_meetup_oct_2015_us_bancorp_tower
                • 26503
                • 620 Posts
                right the table is actually called 'active_users' ~ basically sessions I was assuming.

                I basically downloaded the whole site, deleted the live files - cleaned all the infected files, re-uploaded then did an upgrade

                Cache has been clear multiple times.

                Previous dev is MIA.

                The only place I see the user id as a negative is in the active users table, the web_users table uses all positive integers.

                I see a 'sessions' folder in the server root, but it is empty.. that's a new one on me.


                Quote from: mrhaw at Jul 03, 2014, 11:50 AM
                > I don't know... EVO has no session_table in the db. Is this setup connected to EVO's web user handling at all?

                > How did you do the upgrade? Did you clear cache before and after? Did you click to overwrite weblogin snippet and files?
                Can you get up the old site to compare with?

                > Can you get a hold of the previous developer for a dialouge?

                > In EVO web-users has a negative integer and mgr-users a positive...

                > Have you wiped the stored sessions on the server and locally.

                  *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

                  Sean Kimball CLP, CLS.
                  Technical Director / Sr. Developer | BigBlock Studios
                  ._______________________________________________.
                  Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
                  27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
                  phone/fax: 905-426-5525
                  • 26503
                  • 620 Posts
                  I found another session directory in assets/session - set both to 777 neither one gets anything written to it after/during a login.
                    *** Not just websites, we also create signage, banners, print, trade show displays and more! ***

                    Sean Kimball CLP, CLS.
                    Technical Director / Sr. Developer | BigBlock Studios
                    ._______________________________________________.
                    Bigblock Studios http://www.bigblockstudios.ca Web site design & development.
                    27-1300 King Street East. Box 167 Oshawa, Ontario L1H8J4 Canada.
                    phone/fax: 905-426-5525