Hi,
I have a site running on 2.2.2pl which recently had the Core Services hack - I have since removed the core services plugin and had a look for dodgy PHP files / users etc... I also changed all MODx admin passwords and FTP etc - thought had sorted the issue... but now have noticed that on 2 certain pages in the site - that in a table of data where I have some images - the img src elements have been hacked to include a load of spam / crap code... e.g.
img src="data:image/jpeg;base64,/9j/4AAQSkZJRgABAgEAlgCWAAD/7QAsUGhvdG9zaG9wIDMuMAA4QklNA+0AAAAAABAAlgAAAAEAAQCWAAAAAQAB/+"
This is a shortened example - its actually loads and loads of random characters...
So.. question is... how is this happening? I can change the code back to the correct img src and all is fine for a few weeks - and then bang, it happens again...
Any ideas where to search for the dodgy code performing this injection?
Any ideas on a fix?
I am going to be upgrading to a much more recent MODx build, but wanted to remove the malware before that upgrade.
Cheers,
dubbs.