Digital Mouse Designs
  • Email
  • Twitter
  • Rss
  • Home
  • Help
    • Payment Center
      • Make an Online Payment
    • Billing Policy
    • The Blog Rules
    • eMail Help
  • Web Design
    • Get a Web Design Estimate
    • Web Site Design Services
    • Be Upfront About Your Web Design Budget
    • How the Design Process Works
    • Preparing For Your Website
    • Do-It Yourself Websites
    • Where Do I Start?
    • Communicate Cooperate
    • Choosing Your Web Designer
    • The Client’s Learning Curve
    • Web Site Maintenance
    • Web Site Consultations
    • Web Site Sub-Contracting
    • About Copyright Law
    • We Respect No!Spec
  • WebFolio
    • About Design Portfolios
  • Websites FAQ
    • Can I Update My Own Site?
    • How Is My Site Found?
    • How Long Does It Take to Build a Website?
    • How Much Will My Web Site Cost?
    • What’s a Browser?
    • What’s a Domain Name?
    • What’s a Website Redo?
    • What’s Search Engine Ranking?
    • What’s Web Hosting?
    • Who Owns My Website?
    • Why Do I Need a Designer?
  • SEO
    • SEO 101
    • SEO – a Reality Check
    • SEO is Also YOUR Job
    • About Reciprocal Linking
    • SEO Evaluations
    • SEO Plans
  • Web Hosting
    • About the Hosting Plans
    • Plans & Pricing
    • Register Hosting Account
    • FREE Web Hosting
  • About DMD
    • Meet Keith the Logo Guy
  • Contact

TimThumb SECURITY VULNERABILITY Hits WordPress Sites

August 23, 2011 › On Wordpress

Tonight I learned about a recent security breach involving WordPress sites that use the super-popular TimThumb script which resizes images on they fly — such as automatically creating your thumbnails for example. You need to know and understand that this is not something your hosting company or your designer is responsible for. TimThumb is in use by probably hundreds of thousands of WordPress sites and is automatically included in many WordPress themes but most commonly in the premium (paid) themes.

WPMU.org reports: “Timthumb is a very, very popular script and so it is worth checking to see if you are using it in your theme. If you are resizing a lot of images as thumbnails then it’s quite possible that it is being used. Of course, these days WordPress can do this itself but TimThumb does increase flexibility.“

It’s things like this happening to WordPress sites that helps keep the “hate” part of my love-hate relationship with it alive. Because it is so darn popular — WordPress is an automatic target for hacking and things like script vulnerability. This doesn’t mean that the developer of your theme, WordPress itself or the developers of TimThumb are no-good-dirty-so and so’s. Theme developers have used the TimThumb script for a very long time without any trouble whatsoever and there are fixes available. You should check with the developer of your theme to determine the fix for your specific theme.

List of Known Theme Makers Who Use TimThumb

WPMU.org also provides the following list list of major theme-makers who utilize the Tim Thumb script in their themes. It should not be considered a complete list. If your theme was made by one of the developers listed, you should visit their websites to obtain more information on the fix for your specific theme. If your theme developer isn’t on this list, you should check their website.

  • Woo Themes – update your theme or the code in thumb.php
  • Templatic – thumb.php script does not use $allowedSites so not affected
  • Elegant Themes – update to latest version
  • Theme Shift – update theme or change code to latest version of timthumb
  • Theme Lab – 3 themes using timthumb. Fix provided at link

What’s the Cost to Fix?

You should not expect your website developer will fix this for free! This is not something that he or she has any control over. If you’re going to have a website you can expect things like this to happen whether your site runs on WordPress or not.

Hackers and script issues are everywhere. Unfortunately, we’re all at their mercy when it comes to what site will be found to have a security problem or what site hackers will attack next and how. You should consider this kind of thing to be part of the cost of having a website and that this time it just happens to affect users of TimThumb. If I were  a client I would expect to be charged the designer’s hourly rate to apply whatever fix is appropriate for your theme. Check with your designer on the cost.

Help Protect Your Website!

For those of you who don’t make it a habit to visit your own website regularly — you must make this a priority on your To-Do list! You may not be lucky enough to have some kind soul notify you that your site is down or has been hacked. Visiting your own site may be the first or only way to know. If you don’t follow this one simple step — your site could be down or trashed by hackers for a very long time before you notice it — but your site visitors will! I visit each of my websites at least weekly and sometimes more often just to be sure everything is ok.

security vulnerability in tim thumb script, tim thumb script vulnerability

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

LOOKING for Something?

Lucy Writes:

"Wow! Deb offers professional service, along with easy to understand answers. I am not very tech savvy, but whenever I ask questions, Deb takes the time to give me a thorough explanation that analyzes the issue, offers multiple options and gives a professional recommendation. I have felt Deb was looking out for my best interests in her guidance. She knows her stuff and then some! I can highly recommend Deb as an honest and experienced professional! She's simply a joy!" ~ Lucy Armistead

Newsletter Subscriptions

How would you like to receive your newsletters?

Published no more than six times per year. Your subscription eMail address will not be sold, rented or given to any third party.

BLOG Topics

  • Web Site Design
  • Do-It Yourself Web Sites
  • Client-Designer Relationships
  • Tips for a Better Website
  • On Wordpress
  • Search Engine Optimization A.K.A. SEO
  • Blogging
  • Social Networking
  • Content Management Systems
  • Site Maintenance
  • Everything Else!

Newest BLOG Entries

  • Spring Brings Brute Force Attacks on WordPress sites
  • Avoiding Penalties from the Link Police
  • I’m Afraid My Web Designer Owns My Website!
  • Have You Hugged Your Website Lately?
  • WANTED: The WOW Factor!

BLOG Commentary

  • Frases 140 on Displaying Quotes on Your Website
  • Deb on What’s This Gibberish on My Website?
  • Deb on I’m Afraid My Web Designer Owns My Website!
  • Afrazz on What’s This Gibberish on My Website?
  • Melanie on I’m Afraid My Web Designer Owns My Website!

Blog ARCHIVES

How much does a website cost?

Convenient Flexible PAYMENT OPTIONS

Solution Graphics
Wordpress Tutorials from Digital Mouse Designs

WEBFOLIO Samples

Lab Adoption Talk Therapy Biz Boy Scout Troop 2002 Deluxe34

We Respect No!Spec

and YOU should, too!

NoSpec

Click Here to Learn Why

ASSOCIATES Corner

  • 123 Web Designer Directory
  • DBK Web Development
  • Digital Spinner
  • ExactSeek
  • Freelance Designers Web Design
  • Hometown USA Directory
  • It's Web Related
  • Keith Doles Graphic Designer
  • SEO Web Design
  • The Link List Directory
  • Wise Women Designers
  • Women Designer’s Group

This Website

Protected by Copyscape Unique Content Check

(c) 1996 and Beyond - Deb's Web LLC - DBA Digital Mouse Designs - Website Design & Development - Watertown, WI