Timthumb.php Exploit

I’ll make this real short, but there is an exploit that takes advantage of timthumb.php that comes included in many WordPress themes. The exploit modifies your website so that all search engines think you have moved all your content to a new site and tells them to remove your site from search results.

What’s tricky about this exploit is that when you or someone else visits your website, everything works fine giving you the impression all is well; by the time you find out what happened, it’s too late and you could be a year or more trying to recover.

What can you do? Check for a massive base64 encoded string in your sites files (it would span multiple lines) and look at your htaccess file for unusual modifications.

If your traffic is dead or dieing and you’re using WordPress, you better check to make sure you haven’t been hit with this exploit!

Details on removal found at auditmypc.com/timthumb-php-vulnerability.asp

Good luck!

VN:F [1.9.14_1148]
Rating: 9.4/10 (16 votes cast)
Timthumb.php Exploit , 9.4 out of 10 based on 16 ratings

Speak Your Mind