Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 27

Thread: Update your timthumb.php! Otherwise, you'll get hacked!

  1. #11
    Veteran spymare's Avatar
    Join Date
    Aug 2010
    Location
    Denmark
    Posts
    871
    Thanks
    16
    Thanked 82 Times in 61 Posts
    at least woothemes takes their customers seriously (appthemes does not) acutally not at all, actually not even close..

    sanook thanks for the tip but regarding bulletproof plugin, I have used it earlier, and had some access problems with it

  2. #12
    Veteran barukar's Avatar
    Join Date
    Sep 2010
    Location
    Brasil, São Paulo, SP
    Posts
    6,785
    Thanks
    186
    Thanked 742 Times in 623 Posts
    Quote Originally Posted by sanook View Post
    This should be top priority. It´s very easy to update all themes with the timthumb version 2 and to put a message on the blog.

    I really can not believe there has been taken no action on this after 10 days. I´m very very sorry to say, but does AppThemes take there customers seriously?

    Sanook is disappointed in AppThemes.
    Already a requested position of the team of developers and have an answer soon.
    I am very thankful for all the help you are giving in relation to this issue, and I will mark this thread is sticky
    -------------------------------------------------------------------------------------------
    Projects: ClassiNoiva - Classimóveis - vocênoenem - i50 - Clube DETRAN

  3. #13
    Junior Member exoticvintage's Avatar
    Join Date
    Aug 2011
    Posts
    37
    Thanks
    10
    Thanked 1 Time in 1 Post
    Quote Originally Posted by sanook View Post
    Spymare,

    If you're not infected

    One method is:

    Go to WP-dashboard, appearance -> editor, find "timthumb.php -> delete all code, paste this code there.

    If you are infected, also get rid of all the .htaccess files (root and theme-folders) and replace with authentic ones.

    For all people using Wordpress, install the Bulletproof Security Plugin
    Just to be sure I do this properly... (I am a newbie). I replace with all of the code in the link above?

  4. #14
    Thread Starter
    Senior Member sanook's Avatar
    Join Date
    Mar 2011
    Location
    Thailand
    Posts
    162
    Thanks
    28
    Thanked 15 Times in 12 Posts
    Exoticvintage,

    Yes, replace ALL the old code by ALL the new code.

    Now you have Timthumb version 2.
    Feel free to have a look at my creation: MarketplaceThailand.com

  5. The Following User Says Thank You to sanook For This Useful Post:

    exoticvintage (August 15th, 2011)

  6. #15
    Thread Starter
    Senior Member sanook's Avatar
    Join Date
    Mar 2011
    Location
    Thailand
    Posts
    162
    Thanks
    28
    Thanked 15 Times in 12 Posts
    Quote Originally Posted by barukar View Post
    [...]I am very thankful for all the help you are giving in relation to this issue[...]
    You're welcome
    Feel free to have a look at my creation: MarketplaceThailand.com

  7. The Following User Says Thank You to sanook For This Useful Post:

    Bredvig (August 15th, 2011)

  8. #16
    Member Bredvig's Avatar
    Join Date
    Jul 2010
    Location
    Dublin, Ireland
    Posts
    70
    Thanks
    2
    Thanked 10 Times in 7 Posts
    Just updated mine... Many thanks for the headsup Sanook.

    I'm sure that AppTheme do take this security issue serious as much as any other Wordpress theme developers. However at update on the front page of the site would have been nice. In that case we would know about it.

    I did not know this until I saw this thread.

    Bredvig.

  9. #17
    pepsi's Avatar
    Join Date
    Mar 2009
    Location
    New Zealand
    Posts
    14,883
    Thanks
    91
    Thanked 804 Times in 718 Posts
    Thanks sanook for raising these concerns and sharing a solution.

    We will be rolling out a patch (3.1.4) shortly to address this. Customers who purchased CP AFTER 4/01/10 (v3.0+) do NOT need TimThumb and can just delete it (/includes/timthumb.php). It was left in there for legacy support.

    Everyone else should follow the instructions as mentioned by sanook or wait for the patch to go out.

    We'll also be emailing all customers to advise them of this. Thanks.

  10. #18
    Member Bredvig's Avatar
    Join Date
    Jul 2010
    Location
    Dublin, Ireland
    Posts
    70
    Thanks
    2
    Thanked 10 Times in 7 Posts
    The patch you are going to release soon. Will that only address this issue, or will other fixes be looked at as well? Just want to know if I should need to do the update of the theme in due time.

  11. #19
    pepsi's Avatar
    Join Date
    Mar 2009
    Location
    New Zealand
    Posts
    14,883
    Thanks
    91
    Thanked 804 Times in 718 Posts
    The patch is primarily to address this timthumb issue and is scheduled within the next couple of days.

  12. #20
    Member Bredvig's Avatar
    Join Date
    Jul 2010
    Location
    Dublin, Ireland
    Posts
    70
    Thanks
    2
    Thanked 10 Times in 7 Posts
    Ok great. No worries for me then as I followed Sanooks advice yesterday.

Page 2 of 3 FirstFirst 123 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. [SOLVED] TimThumb vulnerability?
    By rodeoramsey in forum Report ClassiPress Bugs
    Replies: 2
    Last Post: October 23rd, 2011, 04:44 PM
  2. Have I been hacked?
    By Almost in forum WordPress General Discussion
    Replies: 14
    Last Post: August 31st, 2011, 01:52 PM
  3. Timthumb (thumb.php) Security Flaw
    By sanook in forum WordPress General Discussion
    Replies: 1
    Last Post: August 14th, 2011, 10:16 AM
  4. converting timthumb cached images to actual files
    By mlepisto in forum ClassiPress General Discussion
    Replies: 0
    Last Post: January 17th, 2011, 12:22 PM