Quote from: g5604 at Dec 17, 2014, 03:09 AMthank you! great advice.
$this->_sourcePath= $this->xpdo->getOption('element_static_path', $options, $this->xpdo->getOption('components_path', $options, MODX_CORE_PATH . 'components/'));
Seems like you had the same hack as what i had. They'd some how installed a snippet called getMessage and embedded this into the home template.
First thought maybe the passwords had been compromised but the ID of the snippet was non-sequential, 4000 or something like that. So looks more like a SQLi attack.
I was running the site on a modx cloud so it was update within weeks of any new releases if not days.
I'd passed info over to modx cloud guys but not sure if they managed to find an holes where it would of been compromised.
It was a cleaver hack as if the site was viewed directly you didn't notice anything, but if clicked on via google search results it was looking for google headers and then redirected you to another site.
So it went un noticed for a while, which was annoying as I could no longer roll back to a cloud back up.