G
define ('ALLOW_EXTERNAL', false);
$ AllowedSites = array (
"Flickr.com",
'Picasa.com',
'Img.youtube.com',
'Upload.wikimedia.org',
);
$ AllowedSites = array ();
ahi lo estoy probando..
a mi me paso hace un par de seanas...
hay una opcion para hacer update del archivo vulnerable... eso lo probaste?
sobre el aviso de wordpress, al menos a mi me avisa google por medio del webmaster tool
me manda mails cuando hay una version nueva de wordpress pero no se si de plugs hay algo
Mejor no utilicéis timthumb... utilizad las funciones de WordPress para manejar imágenes.
Enlace eliminado
Encontré este plugin para actualizar a versiones sin problemas *se supone
WordPress › Timthumb Vulnerability Scanner « WordPress Plugins
desgraciadamente la plantilla de mi cliente lo usa, y el programador de la plantilla es bastante chapuzas, por no hablar de que le dio pereza lanzar la versión archivo actualizado hasta semanas después de que se descubrió el problema
$ AllowedSites = array ();
$ALLOWED_SITES = array ();
pues si me explicas cómo...
<?php echo mostrar_img(get_the_ID(),'m160'); ?>
if(function_exists('add_image_size')){
add_image_size('m160', 160, 120, true);
add_image_size('m146', 146, 108, true);
}
function mostrar_img($id,$tam){
$files = get_children("post_parent=$id&post_type=attachment&post_mime_type=image");
if($files){
$keys = array_keys($files);
$thumb=wp_get_attachment_image_src($keys[0], $size = $tam, $icon = false);
return $thumb[0];
}
}
173.245.53.154 - - [19/Apr/2012:12:27:56 +0000] "GET /wp-content/themes/8q/scripts/timthumb.php HTTP/1.1" 404 5755
173.245.53.154 - - [19/Apr/2012:12:27:57 +0000] "GET /wp-content/themes/aerial/lib/timthumb.php HTTP/1.1" 404 5759
173.245.53.154 - - [19/Apr/2012:12:27:57 +0000] "GET /wp-content/themes/aesthete/timthumb.php HTTP/1.1" 404 5756
173.245.53.154 - - [19/Apr/2012:12:27:58 +0000] "GET /wp-content/themes/albizia/includes/timthumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:27:58 +0000] "GET /wp-content/themes/amphion-lite/script/timthumb.php HTTP/1.1" 404 5762
173.245.53.154 - - [19/Apr/2012:12:27:59 +0000] "GET /wp-content/themes/aqua-blue/includes/timthumb.php HTTP/1.1" 404 5761
173.245.53.154 - - [19/Apr/2012:12:27:59 +0000] "GET /wp-content/themes/aranovo/scripts/timthumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:28:00 +0000] "GET /wp-content/themes/arras/library/timthumb.php HTTP/1.1" 404 5761
173.245.53.154 - - [19/Apr/2012:12:28:01 +0000] "GET /wp-content/themes/arras-theme/library/timthumb.php HTTP/1.1" 404 5763
173.245.53.154 - - [19/Apr/2012:12:28:02 +0000] "GET /wp-content/themes/arthemix-bronze/scripts/timthumb.php HTTP/1.1" 404 5764
173.245.53.154 - - [19/Apr/2012:12:28:02 +0000] "GET /wp-content/themes/arthemix-green/scripts/timthumb.php HTTP/1.1" 404 5761
173.245.53.154 - - [19/Apr/2012:12:28:03 +0000] "GET /wp-content/themes/artisan/includes/timthumb.php HTTP/1.1" 404 5759
173.245.53.154 - - [19/Apr/2012:12:28:03 +0000] "GET /wp-content/themes/a-simple-business-theme/scripts/timthumb.php HTTP/1.1" 404 5767
173.245.53.154 - - [19/Apr/2012:12:28:04 +0000] "GET /wp-content/themes/a-supercms/timthumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:28:05 +0000] "GET /wp-content/themes/aureola/scripts/timthumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:28:05 +0000] "GET /wp-content/themes/aurorae/timthumb.php HTTP/1.1" 404 5755
173.245.53.154 - - [19/Apr/2012:12:28:06 +0000] "GET /wp-content/themes/autofashion/thumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:28:07 +0000] "GET /wp-content/themes/automotive-blog-theme/Quick%20Cash%20Auto/timthumb.php HTTP/1.1" 404 5781
173.245.53.154 - - [19/Apr/2012:12:28:08 +0000] "GET /wp-content/themes/automotive-blog-theme/timthumb.php HTTP/1.1" 404 5763
173.245.53.154 - - [19/Apr/2012:12:28:09 +0000] "GET /wp-content/themes/bikes/thumb.php HTTP/1.1" 404 5753
173.245.53.154 - - [19/Apr/2012:12:28:10 +0000] "GET /wp-content/themes/black_eve/timthumb.php HTTP/1.1" 404 5755
173.245.53.154 - - [19/Apr/2012:12:28:10 +0000] "GET /wp-content/themes/blex/scripts/timthumb.php HTTP/1.1" 404 5756
173.245.53.154 - - [19/Apr/2012:12:28:11 +0000] "GET /wp-content/themes/bloggnorge-a1/scripts/timthumb.php HTTP/1.1" 404 5763
173.245.53.154 - - [19/Apr/2012:12:28:11 +0000] "GET /wp-content/themes/blogified/timthumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:28:12 +0000] "GET /wp-content/themes/blue-corporate-hyve-theme/timthumb.php HTTP/1.1" 404 5766
173.245.53.154 - - [19/Apr/2012:12:28:13 +0000] "GET /wp-content/themes/bluemag/library/timthumb.php HTTP/1.1" 404 5761
173.245.53.154 - - [19/Apr/2012:12:28:13 +0000] "GET /wp-content/themes/blue-news/scripts/timthumb.php HTTP/1.1" 404 5761
173.245.53.154 - - [19/Apr/2012:12:28:14 +0000] "GET /wp-content/themes/bombax/includes/timthumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:28:15 +0000] "GET /wp-content/themes/breakingnewz/timthumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:28:15 +0000] "GET /wp-content/themes/brightsky/scripts/timthumb.php HTTP/1.1" 404 5759
173.245.53.154 - - [19/Apr/2012:12:28:16 +0000] "GET /wp-content/themes/brochure-melbourne/includes/timthumb.php HTTP/1.1" 404 5767
173.245.53.154 - - [19/Apr/2012:12:28:17 +0000] "GET /wp-content/themes/business-turnkey/assets/js/timthumb.php HTTP/1.1" 404 5770
173.245.53.154 - - [19/Apr/2012:12:28:17 +0000] "GET /wp-content/themes/calotropis/includes/timthumb.php HTTP/1.1" 404 5761
173.245.53.154 - - [19/Apr/2012:12:28:18 +0000] "GET /wp-content/themes/coffee-lite/thumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:28:18 +0000] "GET /wp-content/themes/comet/scripts/timthumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:28:19 +0000] "GET /wp-content/themes/conceditor-wp-strict/scripts/timthumb.php HTTP/1.1" 404 5766
173.245.53.154 - - [19/Apr/2012:12:28:20 +0000] "GET /wp-content/themes/constructor/layouts/thumb.php HTTP/1.1" 404 5762
173.245.53.154 - - [19/Apr/2012:12:28:20 +0000] "GET /wp-content/themes/constructor/libs/timthumb.php HTTP/1.1" 404 5763
173.245.53.154 - - [19/Apr/2012:12:28:21 +0000] "GET /wp-content/themes/constructor/timthumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:28:22 +0000] "GET /wp-content/themes/coverht-wp/scripts/timthumb.php HTTP/1.1" 404 5761
173.245.53.154 - - [19/Apr/2012:12:28:22 +0000] "GET /wp-content/themes/cover-wp/scripts/timthumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:28:23 +0000] "GET /wp-content/themes/dark-dream-media/timthumb.php HTTP/1.1" 404 5762
173.245.53.154 - - [19/Apr/2012:12:28:26 +0000] "GET /wp-content/themes/deep-blue/timthumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:28:26 +0000] "GET /wp-content/themes/delicate/thumb.php HTTP/1.1" 404 5753
173.245.53.154 - - [19/Apr/2012:12:28:26 +0000] "GET /wp-content/themes/diamond-ray/thumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:28:27 +0000] "GET /wp-content/themes/dieselclothings/thumb.php HTTP/1.1" 404 5759
173.245.53.154 - - [19/Apr/2012:12:28:27 +0000] "GET /wp-content/themes/digitalblue/thumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:28:28 +0000] "GET /wp-content/themes/dimenzion/timthumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:28:28 +0000] "GET /wp-content/themes/epione/script/timthumb.php HTTP/1.1" 404 5755
173.245.53.154 - - [19/Apr/2012:12:28:29 +0000] "GET /wp-content/themes/evr-green/scripts/timthumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:28:29 +0000] "GET /wp-content/themes/famous/megaframe/megapanel/inc/upload.php HTTP/1.1" 404 5773
173.245.53.154 - - [19/Apr/2012:12:28:30 +0000] "GET /wp-content/themes/famous/timthumb.php HTTP/1.1" 404 5755
173.245.53.154 - - [19/Apr/2012:12:28:31 +0000] "GET /wp-content/themes/fashion-style/thumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:28:32 +0000] "GET /wp-content/themes/featuring/timthumb.php HTTP/1.1" 404 5756
173.245.53.154 - - [19/Apr/2012:12:28:33 +0000] "GET /wp-content/themes/fliphoto/timthumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:28:33 +0000] "GET /wp-content/themes/flix/timthumb.php HTTP/1.1" 404 5754
173.245.53.154 - - [19/Apr/2012:12:28:33 +0000] "GET /wp-content/themes/fordreporter/scripts/thumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:28:35 +0000] "GET /wp-content/themes/freeside/thumb.php HTTP/1.1" 404 5754
173.245.53.154 - - [19/Apr/2012:12:28:36 +0000] "GET /wp-content/themes/fresh-blu/scripts/timthumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:28:36 +0000] "GET /wp-content/themes/go-green/modules/timthumb.php HTTP/1.1" 404 5761
173.245.53.154 - - [19/Apr/2012:12:28:37 +0000] "GET /wp-content/themes/granite-lite/scripts/timthumb.php HTTP/1.1" 404 5762
173.245.53.154 - - [19/Apr/2012:12:28:37 +0000] "GET /wp-content/themes/greydove/timthumb.php HTTP/1.1" 404 5756
173.245.53.154 - - [19/Apr/2012:12:28:37 +0000] "GET /wp-content/themes/greyzed/functions/efrog/lib/timthumb.php HTTP/1.1" 404 5769
173.245.53.154 - - [19/Apr/2012:12:28:38 +0000] "GET /wp-content/themes/gunungkidul/thumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:28:38 +0000] "GET /wp-content/themes/heartspotting-beta/thumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:28:39 +0000] "GET /wp-content/themes/heli-1-wordpress-theme/images/timthumb.php HTTP/1.1" 404 5762
173.245.53.154 - - [19/Apr/2012:12:28:40 +0000] "GET /wp-content/themes/ideatheme/timthumb.php HTTP/1.1" 404 5756
173.245.53.154 - - [19/Apr/2012:12:28:41 +0000] "GET /wp-content/themes/impressio/timthumb/timthumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:28:41 +0000] "GET /wp-content/themes/introvert/thumb.php HTTP/1.1" 404 5753
173.245.53.154 - - [19/Apr/2012:12:28:42 +0000] "GET /wp-content/themes/inuit-types/thumb.php HTTP/1.1" 404 5756
173.245.53.154 - - [19/Apr/2012:12:28:42 +0000] "GET /wp-content/themes/isotherm-news/thumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:28:43 +0000] "GET /wp-content/themes/iwana-v10/timthumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:28:43 +0000] "GET /wp-content/themes/jambo/thumb.php HTTP/1.1" 404 5752
173.245.53.154 - - [19/Apr/2012:12:28:44 +0000] "GET /wp-content/themes/jcblackone/thumb.php HTTP/1.1" 404 5755
173.245.53.154 - - [19/Apr/2012:12:28:44 +0000] "GET /wp-content/themes/kratalistic/thumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:28:45 +0000] "GET /wp-content/themes/life-style-free/thumb.php HTTP/1.1" 404 5756
173.245.53.154 - - [19/Apr/2012:12:28:46 +0000] "GET /wp-content/themes/likehacker/timthumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:28:47 +0000] "GET /wp-content/themes/litepress/scripts/timthumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:28:47 +0000] "GET /wp-content/themes/loganpress-premium-theme-1/thumb.php HTTP/1.1" 404 5765
173.245.53.154 - - [19/Apr/2012:12:28:48 +0000] "GET /wp-content/themes/magazine-basic/thumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:28:49 +0000] "GET /wp-content/themes/magup/timthumb.php HTTP/1.1" 404 5754
173.245.53.154 - - [19/Apr/2012:12:28:49 +0000] "GET /wp-content/themes/make-money-online-theme-1/scripts/timthumb.php HTTP/1.1" 404 5766
173.245.53.154 - - [19/Apr/2012:12:28:50 +0000] "GET /wp-content/themes/make-money-online-theme-2/scripts/timthumb.php HTTP/1.1" 404 5766
173.245.53.154 - - [19/Apr/2012:12:28:51 +0000] "GET /wp-content/themes/make-money-online-theme-3/scripts/timthumb.php HTTP/1.1" 404 5766
173.245.53.154 - - [19/Apr/2012:12:28:51 +0000] "GET /wp-content/themes/make-money-online-theme-4/scripts/timthumb.php HTTP/1.1" 404 5766
173.245.53.154 - - [19/Apr/2012:12:28:53 +0000] "GET /wp-content/themes/make-money-online-theme/scripts/timthumb.php HTTP/1.1" 404 5766
173.245.53.154 - - [19/Apr/2012:12:28:53 +0000] "GET /wp-content/themes/meintest/layouts/thumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:28:54 +0000] "GET /wp-content/themes/mobilephonecomparision/thumb.php HTTP/1.1" 404 5763
173.245.53.154 - - [19/Apr/2012:12:28:54 +0000] "GET /wp-content/themes/moi-magazine/timthumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:28:55 +0000] "GET /wp-content/themes/my-heli/images/timthumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:28:55 +0000] "GET /wp-content/themes/mymag/timthumb.php HTTP/1.1" 404 5753
173.245.53.154 - - [19/Apr/2012:12:28:56 +0000] "GET /wp-content/themes/mystique/extensions/auto-thumb/timthumb.php HTTP/1.1" 404 5768
173.245.53.154 - - [19/Apr/2012:12:28:57 +0000] "GET /wp-content/themes/nash/theme-assets/php/timthumb.php HTTP/1.1" 404 5762
173.245.53.154 - - [19/Apr/2012:12:28:57 +0000] "GET /wp-content/themes/neofresh/timthumb.php HTTP/1.1" 404 5756
173.245.53.154 - - [19/Apr/2012:12:28:58 +0000] "GET /wp-content/themes/neo_wdl/includes/extensions/thumb.php HTTP/1.1" 404 5763
173.245.53.154 - - [19/Apr/2012:12:28:58 +0000] "GET /wp-content/themes/new-green-natural-living-ngnl/scripts/timthumb.php HTTP/1.1" 404 5774
173.245.53.154 - - [19/Apr/2012:12:29:00 +0000] "GET /wp-content/themes/newspress/thumb.php HTTP/1.1" 404 5754
173.245.53.154 - - [19/Apr/2012:12:29:01 +0000] "GET /wp-content/themes/pearlie/scripts/timthumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:29:02 +0000] "GET /wp-content/themes/pico/scripts/timthumb.php HTTP/1.1" 404 5756
173.245.53.154 - - [19/Apr/2012:12:29:03 +0000] "GET /wp-content/themes/postage-sydney/includes/timthumb.php HTTP/1.1" 404 5764
173.245.53.154 - - [19/Apr/2012:12:29:04 +0000] "GET /wp-content/themes/premium-violet/thumb.php HTTP/1.1" 404 5759
173.245.53.154 - - [19/Apr/2012:12:29:05 +0000] "GET /wp-content/themes/probluezine/timthumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:29:06 +0000] "GET /wp-content/themes/pronto/cjl/pronto/uploadify/check.php HTTP/1.1" 404 5767
173.245.53.154 - - [19/Apr/2012:12:29:06 +0000] "GET /wp-content/themes/pronto/cjl/pronto/uploadify/uploadify.php HTTP/1.1" 404 5764
173.245.53.154 - - [19/Apr/2012:12:29:07 +0000] "GET /wp-content/themes/r755/thumb.php HTTP/1.1" 404 5752
173.245.53.154 - - [19/Apr/2012:12:29:08 +0000] "GET /wp-content/themes/regal/timthumb.php HTTP/1.1" 404 5753
173.245.53.154 - - [19/Apr/2012:12:29:09 +0000] "GET /wp-content/themes/shaan/timthumb.php HTTP/1.1" 404 5753
173.245.53.154 - - [19/Apr/2012:12:29:09 +0000] "GET /wp-content/themes/shadow-block/thumb.php HTTP/1.1" 404 5758
173.245.53.156 - - [19/Apr/2012:12:29:11 +0000] "GET /wp-content/themes/shadow/timthumb.php HTTP/1.1" 404 5755
173.245.53.156 - - [19/Apr/2012:12:29:12 +0000] "GET /wp-content/themes/simple-but-great/timthumb.php HTTP/1.1" 404 5761
173.245.53.154 - - [19/Apr/2012:12:29:13 +0000] "GET /wp-content/themes/simplenews_premium/scripts/timthumb.php HTTP/1.1" 404 5766
173.245.53.154 - - [19/Apr/2012:12:29:13 +0000] "GET /wp-content/themes/simple-red-theme/timthumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:29:14 +0000] "GET /wp-content/themes/simple-tabloid/thumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:29:14 +0000] "GET /wp-content/themes/simplewhite/timthumb.php HTTP/1.1" 404 5759
173.245.53.154 - - [19/Apr/2012:12:29:14 +0000] "GET /wp-content/themes/slidette/timThumb/timthumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:29:15 +0000] "GET /wp-content/themes/snowblind_colbert/thumb.php HTTP/1.1" 404 5759
173.245.53.154 - - [19/Apr/2012:12:29:15 +0000] "GET /wp-content/themes/snowblind/thumb.php HTTP/1.1" 404 5755
173.245.53.154 - - [19/Apr/2012:12:29:15 +0000] "GET /wp-content/themes/spotlight/timthumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:29:16 +0000] "GET /wp-content/themes/squeezepage/timthumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:29:16 +0000] "GET /wp-content/themes/standout/thumb.php HTTP/1.1" 404 5751
173.245.53.154 - - [19/Apr/2012:12:29:17 +0000] "GET /wp-content/themes/suffusion/timthumb.php HTTP/1.1" 404 5756
173.245.53.154 - - [19/Apr/2012:12:29:17 +0000] "GET /wp-content/themes/swift/includes/thumb.php HTTP/1.1" 404 5756
173.245.53.154 - - [19/Apr/2012:12:29:18 +0000] "GET /wp-content/themes/swift/includes/timthumb.php HTTP/1.1" 404 5756
173.245.53.154 - - [19/Apr/2012:12:29:19 +0000] "GET /wp-content/themes/swift/timthumb.php HTTP/1.1" 404 5754
173.245.53.154 - - [19/Apr/2012:12:29:20 +0000] "GET /wp-content/themes/techozoic-fluid/options/thumb.php HTTP/1.1" 404 5766
173.245.53.154 - - [19/Apr/2012:12:29:21 +0000] "GET /wp-content/themes/the_dark_os/tools/timthumb.php HTTP/1.1" 404 5762
173.245.53.154 - - [19/Apr/2012:12:29:21 +0000] "GET /wp-content/themes/themetiger-fashion/thumb.php HTTP/1.1" 404 5759
173.245.53.154 - - [19/Apr/2012:12:29:22 +0000] "GET /wp-content/themes/theory/thumb.php HTTP/1.1" 404 5753
173.245.53.154 - - [19/Apr/2012:12:29:22 +0000] "GET /wp-content/themes/the-theme/core/libs/thumbnails/thumb.php HTTP/1.1" 404 5765
173.245.53.154 - - [19/Apr/2012:12:29:23 +0000] "GET /wp-content/themes/thrillingtheme/thumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:29:24 +0000] "GET /wp-content/themes/tm-theme/js/timthumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:29:25 +0000] "GET /wp-content/themes/totallyred/scripts/timthumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:29:25 +0000] "GET /wp-content/themes/travelogue-theme/scripts/timthumb.php HTTP/1.1" 404 5762
173.245.53.154 - - [19/Apr/2012:12:29:25 +0000] "GET /wp-content/themes/true-blue-theme/timthumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:29:26 +0000] "GET /wp-content/themes/ttnews-theme/timthumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:29:27 +0000] "GET /wp-content/themes/twittplus/scripts/timthumb.php HTTP/1.1" 404 5761
173.245.53.154 - - [19/Apr/2012:12:29:27 +0000] "GET /wp-content/themes/typographywp/timthumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:29:28 +0000] "GET /wp-content/themes/ugly/timthumb.php HTTP/1.1" 404 5753
173.245.53.154 - - [19/Apr/2012:12:29:29 +0000] "GET /wp-content/themes/unity/timthumb.php HTTP/1.1" 404 5754
173.245.53.154 - - [19/Apr/2012:12:29:30 +0000] "GET /wp-content/themes/versitility/timthumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:29:31 +0000] "GET /wp-content/themes/vibefolio-teaser-10/scripts/timthumb.php HTTP/1.1" 404 5767
173.245.53.154 - - [19/Apr/2012:12:29:32 +0000] "GET /wp-content/themes/vina/thumb.php HTTP/1.1" 404 5752
173.245.53.154 - - [19/Apr/2012:12:29:33 +0000] "GET /wp-content/themes/whitemag/script/thumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:29:33 +0000] "GET /wp-content/themes/wpapi/thumb.php HTTP/1.1" 404 5753
173.245.53.154 - - [19/Apr/2012:12:29:34 +0000] "GET /wp-content/themes/wpbus-d4/includes/timthumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:29:34 +0000] "GET /wp-content/themes/wp-creativix/scripts/timthumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:29:36 +0000] "GET /wp-content/themes/wp-newsmagazine/scripts/timthumb.php HTTP/1.1" 404 5763
173.245.53.154 - - [19/Apr/2012:12:29:39 +0000] "GET /wp-content/themes/wp-perfect/js/timthumb.php HTTP/1.1" 404 5759
173.245.53.154 - - [19/Apr/2012:12:29:40 +0000] "GET /wp-content/themes/wp-premium-orange/timthumb.php HTTP/1.1" 404 5762
173.245.53.154 - - [19/Apr/2012:12:29:40 +0000] "GET /wp-content/themes/xiando-one/thumb.php HTTP/1.1" 404 5754
173.245.53.154 - - [19/Apr/2012:12:29:41 +0000] "GET /wp-content/themes/zcool-like/timthumb.php HTTP/1.1" 404 5759
173.245.53.154 - - [19/Apr/2012:12:29:41 +0000] "GET /wp-content/themes/zcool-like/uploadify.php HTTP/1.1" 404 5762
173.245.53.154 - - [19/Apr/2012:12:29:43 +0000] "GET /wp-content/themes/lifestyle/timthumb.php HTTP/1.1" 404 5756
173.245.53.154 - - [19/Apr/2012:12:29:43 +0000] "GET /wp-content/themes/sakura/plugins/woo-tumblog/functions/thumb.php HTTP/1.1" 404 5772
173.245.53.154 - - [19/Apr/2012:12:29:47 +0000] "GET /wp-content/themes/Karma/timthumb.php HTTP/1.1" 404 5754
173.245.53.154 - - [19/Apr/2012:12:29:47 +0000] "GET /wp-content/themes/typebased/functions/thumb.php HTTP/1.1" 404 5759
173.245.53.154 - - [19/Apr/2012:12:29:48 +0000] "GET /wp-content/themes/themorningafter/functions/thumb.php HTTP/1.1" 404 5761
173.245.53.154 - - [19/Apr/2012:12:29:49 +0000] "GET /wp-content/themes/swatch/functions/thumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:29:50 +0000] "GET /wp-content/themes/snapshot/functions/thumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:29:51 +0000] "GET /wp-content/themes/skeptical/functions/thumb.php HTTP/1.1" 404 5761
173.245.53.154 - - [19/Apr/2012:12:29:51 +0000] "GET /wp-content/themes/rockstar/functions/thumb.php HTTP/1.1" 404 5759
173.245.53.154 - - [19/Apr/2012:12:29:52 +0000] "GET /wp-content/themes/premiumnews/functions/thumb.php HTTP/1.1" 404 5761
173.245.53.154 - - [19/Apr/2012:12:29:53 +0000] "GET /wp-content/themes/placeholder/functions/thumb.php HTTP/1.1" 404 5761
173.245.53.154 - - [19/Apr/2012:12:29:54 +0000] "GET /wp-content/themes/metamorphosis/functions/thumb.php HTTP/1.1" 404 5761
173.245.53.154 - - [19/Apr/2012:12:29:56 +0000] "GET /wp-content/themes/mainstream/functions/thumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:29:56 +0000] "GET /wp-content/themes/irresistible/functions/thumb.php HTTP/1.1" 404 5761
173.245.53.154 - - [19/Apr/2012:12:29:57 +0000] "GET /wp-content/themes/blogtheme/functions/thumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:29:57 +0000] "GET /wp-content/themes/bueno/functions/thumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:29:58 +0000] "GET /wp-content/themes/gazette/functions/thumb.php HTTP/1.1" 404 5759
173.245.53.154 - - [19/Apr/2012:12:29:58 +0000] "GET /wp-content/themes/announcement/functions/thumb.php HTTP/1.1" 404 5759
173.245.53.154 - - [19/Apr/2012:12:30:00 +0000] "GET /wp-content/themes/argentum/functions/thumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:30:02 +0000] "GET /wp-content/themes/beveled/functions/thumb.php HTTP/1.1" 404 5759
173.245.53.154 - - [19/Apr/2012:12:30:02 +0000] "GET /wp-content/themes/biznizz/thumb.php HTTP/1.1" 404 5756
173.245.53.154 - - [19/Apr/2012:12:30:03 +0000] "GET /wp-content/themes/briefed/functions/thumb.php HTTP/1.1" 404 5759
173.245.53.154 - - [19/Apr/2012:12:30:05 +0000] "GET /wp-content/themes/buro/functions/thumb.php HTTP/1.1" 404 5756
173.245.53.154 - - [19/Apr/2012:12:30:06 +0000] "GET /wp-content/themes/canvas/functions/thumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:30:07 +0000] "GET /wp-content/themes/city-guide/thumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:30:08 +0000] "GET /wp-content/themes/coquette/functions/thumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:30:08 +0000] "GET /wp-content/themes/crisp/functions/thumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:30:08 +0000] "GET /wp-content/themes/currents/functions/thumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:30:09 +0000] "GET /wp-content/themes/diner/functions/thumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:30:09 +0000] "GET /wp-content/themes/editorial/functions/thumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:30:10 +0000] "GET /wp-content/themes/empire/functions/thumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:30:10 +0000] "GET /wp-content/themes/emporium/functions/thumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:30:11 +0000] "GET /wp-content/themes/faultpress/functions/thumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:30:12 +0000] "GET /wp-content/themes/listings/functions/thumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:30:12 +0000] "GET /wp-content/themes/olya/functions/thumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:30:13 +0000] "GET /wp-content/themes/premiere/functions/thumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:30:14 +0000] "GET /wp-content/themes/shelflife/functions/thumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:30:14 +0000] "GET /wp-content/themes/simplicity/functions/thumb.php HTTP/1.1" 404 5762
173.245.53.154 - - [19/Apr/2012:12:30:15 +0000] "GET /wp-content/themes/sliding/functions/thumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:30:16 +0000] "GET /wp-content/themes/statua/functions/thumb.php HTTP/1.1" 404 5757
173.245.53.154 - - [19/Apr/2012:12:30:16 +0000] "GET /wp-content/themes/supportpress/functions/thumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:30:16 +0000] "GET /wp-content/themes/teamster/functions/thumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:30:17 +0000] "GET /wp-content/themes/wikeasi/functions/thumb.php HTTP/1.1" 404 5758
173.245.53.154 - - [19/Apr/2012:12:30:17 +0000] "GET /wp-content/themes/woostore/functions/thumb.php HTTP/1.1" 404 5759
173.245.53.154 - - [19/Apr/2012:12:30:18 +0000] "GET /wp-content/themes/kaboodle/functions/thumb.php HTTP/1.1" 404 5759
173.245.53.154 - - [19/Apr/2012:12:30:18 +0000] "GET /wp-content/plugins/category-grid-view-gallery/includes/timthumb.php HTTP/1.1" 404 5776
173.245.53.154 - - [19/Apr/2012:12:30:19 +0000] "GET /wp-content/plugins/auto-attachments/thumb.php HTTP/1.1" 404 5764
173.245.53.154 - - [19/Apr/2012:12:30:19 +0000] "GET /wp-content/plugins/wp-marketplace/libs/timthumb.php HTTP/1.1" 404 5767
173.245.53.154 - - [19/Apr/2012:12:30:20 +0000] "GET /wp-content/plugins/dp-thumbnail/timthumb/timthumb.php HTTP/1.1" 404 5763
173.245.53.154 - - [19/Apr/2012:12:30:20 +0000] "GET /wp-content/plugins/vk-gallery/lib/timthumb.php HTTP/1.1" 404 5765
173.245.53.154 - - [19/Apr/2012:12:30:21 +0000] "GET /wp-content/plugins/rekt-slideshow/picsize.php HTTP/1.1" 404 5763
173.245.53.154 - - [19/Apr/2012:12:30:22 +0000] "GET /wp-content/plugins/cac-featured-content/timthumb.php HTTP/1.1" 404 5763
173.245.53.154 - - [19/Apr/2012:12:30:22 +0000] "GET /wp-content/plugins/rent-a-car/libs/timthumb.php HTTP/1.1" 404 5765
173.245.53.154 - - [19/Apr/2012:12:30:23 +0000] "GET /wp-content/plugins/lisl-last-image-slider/timthumb.php HTTP/1.1" 404 5768
173.245.53.154 - - [19/Apr/2012:12:30:26 +0000] "GET /wp-content/plugins/islidex/js/timthumb.php HTTP/1.1" 404 5763
173.245.53.154 - - [19/Apr/2012:12:30:26 +0000] "GET /wp-content/plugins/kino-gallery/timthumb.php HTTP/1.1" 404 5764
173.245.53.154 - - [19/Apr/2012:12:30:27 +0000] "GET /wp-content/plugins/cms-pack/timthumb.php HTTP/1.1" 404 5760
173.245.53.154 - - [19/Apr/2012:12:30:28 +0000] "GET /wp-content/plugins/a-gallery/timthumb.php HTTP/1.1" 404 5762
173.245.53.154 - - [19/Apr/2012:12:30:28 +0000] "GET /wp-content/plugins/category-list-portfolio-page/scripts/timthumb.php HTTP/1.1" 404 5775
173.245.53.154 - - [19/Apr/2012:12:30:29 +0000] "GET /wp-content/plugins/really-easy-slider/inc/thumb.php HTTP/1.1" 404 5770
173.245.53.154 - - [19/Apr/2012:12:30:29 +0000] "GET /wp-content/plugins/verve-meta-boxes/tools/timthumb.php HTTP/1.1" 404 5769
173.245.53.154 - - [19/Apr/2012:12:30:30 +0000] "GET /wp-content/plugins/user-avatar/user-avatar-pic.php HTTP/1.1" 404 5762
173.245.53.154 - - [19/Apr/2012:12:30:31 +0000] "GET /wp-content/plugins/extend-wordpress/helpers/timthumb/image.php HTTP/1.1" 404 5767
tambien filezilla te genera un thum.dll, no se si sea un archivo oculto
El thumb no lo genera filezilla, lo genera Windows para guardar las miniaturas de las imagenes o no recuerdo exactamente pero es algo seguro y es un archivo oculto del sistema.
Esta semana he sido victima de hackeo a mi sitio principal, y todo gracias al archivo Timthumb que tienen miles de plantillas wordpress, el cual se usa para re dimensionar las imágenes o thumbails. Gracias a dios la empresa que me da el servicio del servidor bloqueo el uso del archivo.
Así como yo miles de webmaster están vulnerables, si tienen el archivo Timthumb.php en su plantilla.
Tienes que protegerte ahora mismo en caso de que tu plantilla funcione con este archivo para redimensionar los thumbails.
1. Instala este plugin para que escanees la carpeta cache de tumbails de tu plantilla: Timthumb Scanner. Este plugin te dirá los archivos que fueron inyectados por el hacker a tu carpeta CACHE, para que los elimines de inmediato.
2. Luego actualiza Timthumb a la ultima versión desde timthumb - image crop zoom resize management - Google Project Hosting. El archivo actualizado es este: Enlace eliminado
3. Asegúrate que el siguiente parámetro este en FALSE. Por defecto esta en TRUE en el codigo que nos proporcionan.
Insertar CODE, HTML o PHP:define ('ALLOW_EXTERNAL', false);
4. Realizar estos cambios:
Cambiar:
Insertar CODE, HTML o PHP:$ AllowedSites = array ( "Flickr.com", 'Picasa.com', 'Img.youtube.com', 'Upload.wikimedia.org', );
Por:
Insertar CODE, HTML o PHP:$ AllowedSites = array ();
De esta forma pude proteger un poco mi carpeta cache de la plantilla. Cuando use el plugin encontre 24 archivos que fueron inyectados por el hacker en mi servidor... 😡😡😡😡😡😡
Utilizamos cookies y tecnologías similares para los siguientes fines:
¿Aceptas las cookies y estas tecnologías?
Utilizamos cookies y tecnologías similares para los siguientes fines:
¿Aceptas las cookies y estas tecnologías?