We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 51398
    • 3 Posts
    Hi everyone,

    The company I work for has its site running on a 1.0.5 Modx. In the past few weeks we've been hacked several times by hackers using or server to send email spam.

    In the beginning hackers used a vulnerability in a Wordpress blog we removed since. But now hackers are using a vulnerability in Modx to inject php files in the /assets directory once again to send email spam which has lead to our IP being banned.

    Our web host tells us that it's because the /assets folder rights are 777 that hackers manage to use this vulnerability. I guess I could set it to 755 but then the cache doesn't work.

    We are putting up a mirror copy of our website to test an update of our website before doing it on the live version.

    Do you think that will help ? Any advice ?

    Thanks.

    This question has been answered by multiple community members. See the first response.

    • discuss.answer
      • 13226
      • 953 Posts
      I can only suggest you do the standard things:

      Backup the server & database
      Check the users in your current install - see if there are accounts that shouldn't be there, if there are - delete them
      Clean your server completely - delete all files & folders
      Update to the latest version: 1.0.15 - http://modx.com/download/evolution/
      Upload latest install and install the update
      From the old version of your site - go through the files (CSS, JS etc.), images, PDF etc. that are 100% required for the site and re-upload to the new version
      Remove all snippets, Modules & plugins that are not required for the running of your site

      You can CHMOD assets to 705 - everything still works

      Hope that helps a little
      • discuss.answer
        • 9995
        • 1,613 Posts
        1.0.5 is causing the problem. like Iusemodx says, clean your site first before upgrading.
          Evolution user, I like the back-end speed and simplicity smiley
          • 51398
          • 3 Posts
          Thanks, i'll try to upgrade as planned. But do you think it will really prevent a hacker from injecting php files in the /assets directory ?
            • 13226
            • 953 Posts
            Take a look at the changelog for the latest version and you will see how many security updates have been made since 1.0.5

            Your site was probably hacked due to at least one of the vulnerabilities that have since been removed
              • 51398
              • 3 Posts
              Ok, thanks. I managed to upgrade a test version of the website with no major hiccups at first sight (a few missig images and a forgotten php in wayfinder I spent 10 minutes to identify).

              I'll now upgrade the live version and hope it goes as smoothly and will no longer be attacked (I asked my webhost to temporarily disable email function on the server to prevent further hacks).

              Thanks again,