We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 18108
    • 24 Posts
    Hi All.
    I run a Modx that has been compromised. Hosting support says so. I noticed, also, odd files added to /manager directory and sub directories.
    It is an old site that I have been upgrading and have a lot of snippets (some of them custom). The site is OK, and not code was added to my pages.
    MODX version is 1.0.12
    PHP Version 5.3.20
    What I should do next? Could you help me with an advice about how to save this site please?

    Thank you in advance.
      Thank you for Modx, and thank you for your help.
    • Hello,

      The short version is you need to clean up the exploit(s) used on your site, and then secure it (upgrade to 1.0.14 is a start). The cleanup process can be time consuming as you need to review all of the files to check for backdoors. Additionally, you need to treat your hosting account as compromised so all passwords should be changed.

      Alternatively, you can hire someone to perform the cleanup for you. I've done them in the past for clients, with the process generally taking 1-2 hours depending on how it was compromised.
        Patrick | Server Wrangler
        About Me: Website | TweetsMODX Hosting
        • 9995
        • 1,613 Posts
        I get this message asswell while there are no hacks. It happens on a clean install.
        I set it off in config so I stop getting e-mail.
          Evolution user, I like the back-end speed and simplicity smiley