We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 10357
    • 573 Posts
    I have a site that has been hacked, as I understand it the only way to truly fix this is to start from a clean install and try and migrate the content. The site is fortunately defunct, so I am curious as to how the hack could be stopped without such drastic measures.

    So far I have:

    - upgraded modx to 2.3.2
    - updated all plugins
    - removed every bit of malicious code I could find.

    everytime I remove the hackers work, the next day it reappears in a different place. They are able to inject code into the root files. Does this mean there is someone manually doing this? is it via the sftp connection? is there anything I can do to lock the site down?
      • 33996
      • 20 Posts
      1/ change your FTP password asap
      2/ search all changed files. for instantce, this shell command line will search files within the last 24h (see mtime -1)
      find . -type f -mtime -1 -exec ls -lah {} \;
      3/ get from your hosting your http logs files and search for any entries with 'POST' requests. It will perhaps give you how the attack could have been done.
      4/ get your ftp log and have a look for any "put" entries
      5/ change the access rights of your directories and files with your ftp client : files with 404 rights, directories 505 rights. For cache files and file upload directories, files with 604/ and directories 705 (see chmod linux command)
      6/ follow the good advices given here : http://rtfm.modx.com/revolution/2.x/administering-your-site/security/hardening-modx-revolution
      7/ have the last version of Modx installed/upgraded
      8/ become a security pro with OWASP https://www.owasp.org/index.php/Getting_Started
        • 28042 ☆ A M B ☆
        • 24,524 Posts
        Look for unexpected or unusual users and plugins. Look at the Manager's activity log and see if anybody unexpected is doing things in the Manager.

        Check for unexpected .php files on the server. Especially look in directories like assets/images where there shouldn't be any .php files; in fact there should be very few if any .php files in the assets directory at all.

        Since you have done an upgrade, check for files that are older than your new MODX files. Sometimes these malicious .php scripts were installed months or even years ago and not triggered until now.
          Studying MODX in the desert - http://sottwell.com
          Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
          Join the Slack Community - http://modx.org
          • 10357
          • 573 Posts
          thank you! great advice.

          I am trying to find the backdoor for the hack, my logs report this error:

          (ERROR @ /.../.../www/core/model/modx/modelement.class.php : 467) PHP warning: file_exists(): open_basedir restriction in effect. File(/.../.../www/getmessage.php) is not within the allowed path(s):


          I have deleted getmessage.php, but line 467 refers to the following:

          $this->_sourcePath= $this->xpdo->getOption('element_static_path', $options, $this->xpdo->getOption('components_path', $options, MODX_CORE_PATH . 'components/'));
          


          where is this set?
            • 36926
            • 701 Posts
            Quote from: g5604 at Dec 17, 2014, 03:09 AM
            thank you! great advice.

            $this->_sourcePath= $this->xpdo->getOption('element_static_path', $options, $this->xpdo->getOption('components_path', $options, MODX_CORE_PATH . 'components/'));
            



            Seems like you had the same hack as what i had. They'd some how installed a snippet called getMessage and embedded this into the home template.

            First thought maybe the passwords had been compromised but the ID of the snippet was non-sequential, 4000 or something like that. So looks more like a SQLi attack.

            I was running the site on a modx cloud so it was update within weeks of any new releases if not days.

            I'd passed info over to modx cloud guys but not sure if they managed to find an holes where it would of been compromised.

            It was a cleaver hack as if the site was viewed directly you didn't notice anything, but if clicked on via google search results it was looking for google headers and then redirected you to another site.

            So it went un noticed for a while, which was annoying as I could no longer roll back to a cloud back up.




              • 10357
              • 573 Posts
              thanks bennyB, that sounds exactly like my hack (same host as well).