• Resolved HaneD

    (@haned)


    I’ve got someone/bot bombarding all my website with this wp-content/themes/openair/tools/timthumb.php?src=/g0../0d1.gif. They change the theme often times but the rest stays the same. WordPress firewall keeps blocking them, but I would like to know what can I do about it and what are they looking for?

    Thanks
    Hanè

Viewing 8 replies - 1 through 8 (of 8 total)
  • update timthumb. the previous version had a security vulnerability. there are some other threads in the forum talking about it.

    Thread Starter HaneD

    (@haned)

    Is it updated with WordPress or do I have to do it manually?

    Moderator Jan Dembowski

    (@jdembowski)

    Forum Moderator and Brute Squad

    Is it updated with WordPress or do I have to do it manually?

    It’s not really a WordPress issue*, so you need to play it safe. Check and update the code manually.

    https://wptheming.com/2011/08/cleaning-up-the-timthumb-hack/

    See Ipstenu’s comment in that post too.

    *It’s not a WordPress issue because that software that the bot is looking for is not part of the core WordPress installation. It’s part of add-ons such as themes or plugins.

    Moderator Ipstenu (Mika Epstein)

    (@ipstenu)

    ?????? Advisor and Activist

    Do it manually if you haven’t.

    I was hit by that too last night, and I don’t even use TimThumb! Basically they’re scanning servers to see if they MIGHT have it. It’s a pain in the ass.

    Thread Starter HaneD

    (@haned)

    It is pain, my inbox is full of warnings due to this. I’m busy updating all my sites and making sure it is not used. Is it only templates that use this or are there plugins as well?

    plugins as well

    Thread Starter HaneD

    (@haned)

    It seems more plugins use it then themes.

    Moderator Ipstenu (Mika Epstein)

    (@ipstenu)

    ?????? Advisor and Activist

    The current scan bot is looking at themes only.

    https://ipstenu.org/code/apachestatus.html is a snapshot of last night :/ They ended up pegging my server with 70% of all traffic being this. I set my firewall to auto-block anyone who directly hits a page with timthumb.php more than five times in a row from the same IP.

Viewing 8 replies - 1 through 8 (of 8 total)
  • The topic ‘Directory Traversal Attack’ is closed to new replies.