Page 1 of 1

timthumb.php

Posted: 27 Aug 2011, 05:57
by grimurnet
Hi, I was wondering if there is a file named timthumb.php in imagevue?
Because I got a e-mail from my host, telling me they found exploitable timthumb.php
They said it has to be updated to fix this issue.

"The timthumb.php file is a script commonly used in WordPress's (and other software's) themes and plugins to resize images. The exploit allows an attacker to arbitrarily upload and create files and/or folders on your account, which can then be used for a number of malicious tasks, including but not limited to defacement, browser high-jacking and infection, data harvesting and more. After a site has been exploited, it may lead to becoming labeled a "Malicious Website" by Google or other security authorities."

Re: timthumb.php

Posted: 27 Aug 2011, 08:17
by grimurnet
grimurnet wrote:Hi, I was wondering if there is a file named timthumb.php in imagevue?
Because I got a e-mail from my host, telling me they found exploitable timthumb.php
They said it has to be updated to fix this issue.

"The timthumb.php file is a script commonly used in WordPress's (and other software's) themes and plugins to resize images. The exploit allows an attacker to arbitrarily upload and create files and/or folders on your account, which can then be used for a number of malicious tasks, including but not limited to defacement, browser high-jacking and infection, data harvesting and more. After a site has been exploited, it may lead to becoming labeled a "Malicious Website" by Google or other security authorities."
Sorry guys, it doesn't seem to be connected to imagevue, I found it in my wordpress setup. I used a ssh search command and found the bastard :-)
Hope you didn't have to go through all your files to search this issue

Re: timthumb.php

Posted: 02 Sep 2011, 11:25
by Nick
Timthumb is a 3rd-party script used by many Wordpress themes to create thumbnails. This is not connected to Imagevue.