1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Warning for Wordpress users - timthumb.php

Discussion in 'Blogging' started by swaggerer, Aug 23, 2011.

  1. #1
    Hey guys,
    Tons of blogs are being hacked due to outdated themes using very old versions of the timthumb script. Generally this is installed in themes though many plugins use it as well.

    I urge all users of Wordpress to search their theme files and if found update timthumb.php
    http://code.google.com/p/timthumb/
    This is the official URL of the timthumb script.

    More WP Info:
    It's always a good idea to backup your websites at least once a week.
    Always delete unused themes and plugins. You never know what may be a security risk.
    Keep all your WP, plugin, and theme software up to date!
    And never use admin as your username... I mean come on.


    Hope this post helps a few of you.
     
    swaggerer, Aug 23, 2011 IP
  2. siocowiz

    siocowiz Active Member

    Messages:
    97
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    68
    #2
    What do you mean by hacked? You mean they gain access to the files?
     
    siocowiz, Aug 25, 2011 IP
  3. shahilroyhere

    shahilroyhere Well-Known Member

    Messages:
    189
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    130
    #3
    Thanks man for sharing this. Yes it's true. There are also plugins available now to check your timthumb.php for vulnerability issues. So always keep this file updated.
     
    shahilroyhere, Sep 7, 2011 IP
  4. khanter

    khanter Peon

    Messages:
    210
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Why the warning about the username? I use the old default wp theme. I keep up to date as best I can. But I am getting zapped and am getting the feeling that my vulnerability has a lot to do with the hosting zoom servers I am using. Possible or paranoid?
     
    khanter, Sep 9, 2011 IP
  5. powermind

    powermind Peon

    Messages:
    40
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Thanks for the heads up!
    It's always wise to remove plugins which are not updated regularly.
     
    powermind, Sep 9, 2011 IP
  6. khanter

    khanter Peon

    Messages:
    210
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Even if they are not activated?

    It would be extremely useful to have a resource explaining how they do it. This exposing the vulnerabilities and more importantly the fixes one has to implement. Knowledge is power and if you shine a little light into those dark corners the big wide world is not so scary any longer.
     
    khanter, Sep 10, 2011 IP
  7. swaggerer

    swaggerer Active Member

    Messages:
    402
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    60
    #7
    That would be nearly impossible. Because not every plugin is going to have the same vulnerabilities as the next.

    "why the warning about the username"
    Because "admin" is the default username that WP creates. It's the first username any hacker would attempt to use to gain access to your blog if they so desired and attempted to do so. Making it something other than "admin" will at least throw them off.
     
    swaggerer, Oct 5, 2011 IP
  8. khanter

    khanter Peon

    Messages:
    210
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Accepted but if we knew more about the nasties, how they get around and why they get around, it would make dealing with the fall out a lot easier. Getting hacked for the first time is a depressing and isolating experience.
     
    khanter, Oct 5, 2011 IP
  9. masterrio

    masterrio Well-Known Member

    Messages:
    938
    Likes Received:
    13
    Best Answers:
    1
    Trophy Points:
    145
    #9
    The last time I heard about this add-on was that the plugin was updated to the latest version and all those who use timthumb old version needed to upgrade to latest version for security issues. Has anything changed in the recent few weeks again ?
     
    masterrio, Oct 5, 2011 IP
  10. swaggerer

    swaggerer Active Member

    Messages:
    402
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    60
    #10
    I agree, it would be great to have a resource like that but usually it's up to the individual theme and plugin makers to do this. That's why, when I can, I only use these that are still being developed by their authors. Many themes/plugins get abandoned after some time and while they may still technically work in WP it leaves them open to a wide array of vulnerabilities.

    I started this thread over a month ago during the height of the timthumb issue. Not everyone knows that themes using it most likely weren't going to release an update, at least free themes. I've updated it manually on many themes I use and it still works like normal, at least with what I've been using it for it.
     
    swaggerer, Oct 10, 2011 IP