-
☆ A M B ☆
- 24,524 Posts
The head of the company that manages a client's
hosting says that "Cache.php is not a virus but some file MODX
installs when you run an update"
Hi Susan,
Wheres this file supposed to live as I upgraded to 2.1.15 last week and can't see cache.php in the cache folder
Just seen your other post and can confirm that theres no assets/cache.php on my upgrade
-
☆ A M B ☆
- 24,524 Posts
This cache.php is a well-known hack, it's inserted into the assets directory, usually accompanied by a bogus manager user account. It allows arbitrary script execution, and appears to the be the first step of a serious compromise giving control of the site, and in some cases the entire server.
https://forums.modx.com/thread/85986/modx-revolution-2-2-6-hack-appearing-in-assets-folder?page=4#dis-post-501999
I was just shocked that a hosting company would think it was something MODX did when updating, and was nothing to worry about!