<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>New Zero-Day Vulnerability Archives -</title>
	<atom:link href="https://cvtfradio.net/tag/new-zero-day-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>https://cvtfradio.net/tag/new-zero-day-vulnerability/</link>
	<description>Conscious Vibrations from terra firma radio</description>
	<lastBuildDate>Wed, 12 Aug 2015 14:35:34 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>New Zero-Day Vulnerability Discovered in TimThumb Script</title>
		<link>https://cvtfradio.net/2014/10/how-to-get-outstanding-urban-night-photographs/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=how-to-get-outstanding-urban-night-photographs</link>
		
		<dc:creator><![CDATA[L3gsman]]></dc:creator>
		<pubDate>Fri, 03 Oct 2014 09:51:21 +0000</pubDate>
				<category><![CDATA[Media]]></category>
		<category><![CDATA[Portfolio]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[New Zero-Day Vulnerability]]></category>
		<guid isPermaLink="false">http://spotlight.themerex.net/?p=1803</guid>

					<description><![CDATA[<p><img width="1016" height="471" src="https://cvtfradio.net/wp-content/uploads/2014/10/alert.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" srcset="https://cvtfradio.net/wp-content/uploads/2014/10/alert.jpg 1016w, https://cvtfradio.net/wp-content/uploads/2014/10/alert-300x139.jpg 300w" sizes="(max-width: 1016px) 100vw, 1016px" /></p>
<p>WordPress Security Alert: New Zero-Day Vulnerability Discovered in TimThumb Script Sarah Gooding June 25, 2014 20 photo credit: kama17 – cc Security vulnerabilities have plagued the TimThumb script for years. It is most commonly used in cropping, zooming and resizing images in WordPress themes. After the large scale attacks launched against the script a few [&#8230;]</p>
<p>The post <a href="https://cvtfradio.net/2014/10/how-to-get-outstanding-urban-night-photographs/">New Zero-Day Vulnerability Discovered in TimThumb Script</a> appeared first on <a href="https://cvtfradio.net"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<header class="entry-header">
<h1 class="entry-title font-headlines">WordPress Security Alert: New Zero-Day Vulnerability Discovered in TimThumb Script</h1>
<div class="entry-byline font-secondary"><span class="entry-author"><a class="url fn n" title="Posts by Sarah Gooding" href="https://wptavern.com/author/sarah" rel="author">Sarah Gooding</a></span> <time class="entry-published updated" title="Wednesday, June 25, 2014, 2:48 pm" datetime="2014-06-25T14:48:35-05:00">June 25, 2014</time> <a class="comments-link" title="Comment on WordPress Security Alert: New Zero-Day Vulnerability Discovered in TimThumb Script" href="https://wptavern.com/wordpress-security-alert-new-zero-day-vulnerability-discovered-in-timthumb-script#comments">20</a></div>
</header>
<div class="entry-content">
<figure id="attachment_25334" class="wp-caption aligncenter" style="width: 719px; text-align: justify;"><figcaption class="wp-caption-text font-secondary">photo credit: <a href="https://www.flickr.com/photos/kama17/9279705214/">kama17</a> – <a href="https://creativecommons.org/licenses/by/2.0/">cc</a></figcaption></figure>
<p style="text-align: justify;">Security vulnerabilities have <a href="https://wptavern.com/timthumb-vulnerability-bites-another-victim" target="_blank">plagued</a> the <a href="https://timthumb.googlecode.com/svn/trunk/timthumb.php" target="_blank">TimThumb</a> script for years. It is most commonly used in cropping, zooming and resizing images in WordPress themes. After the <a href="https://blog.sucuri.net/2011/08/attacks-against-timthumb-php-in-the-wild-list-of-themes-and-plugins-being-scanned.html" target="_blank">large scale attacks</a> launched against the script a few years ago, one might think that theme and plugin developers would be less likely to continue building with it. However, this is not the case and many websites are again in danger, according to the exploit <a href="https://cxsecurity.com/issue/WLB-2014060134" target="_blank">disclosure</a> issued today.</p>
<p style="text-align: justify;">TimThumb 2.8.13 has a vulnerability with its “Webshot” feature that, when enabled, allows attackers to execute commands on a remote website. At this time there is no patch. Security experts at Sucuri <a href="https://blog.sucuri.net/2014/06/timthumb-webshot-code-execution-exploit-0-day.html" target="_blank">break down the threat</a> as follows: <strong>“With a simple command, an attacker can create, remove and modify any files on your server.”</strong></p>
<p style="text-align: justify;">Although the Webshot feature should be disabled by default, Sucuri recommends that you check your timthumb file to make sure it’s disabled. Search for “WEBSHOT_ENABLED” and verify that it’s set to “false,” as shown below:</p>
<div id="highlighter_314875" class="syntaxhighlighter nogutter taverncode " style="text-align: justify;">
<div class="lines">
<div class="line alt1">
<table>
<tbody>
<tr>
<td class="content"><code class="plain">define (‘WEBSHOT_ENABLED’, false);</code></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
<p style="text-align: justify;">This vulnerability affects many WordPress themes, plugins, and third party components. According to the disclosure, all themes from <a href="https://themify.me/" target="_blank">Themify</a> utilize this script, as well as several plugins, including <a href="https://wordpress.org/plugins/wordpress-gallery-plugin/" target="_blank">WordPress Gallery Plugin</a> and the <a href="https://wordpress.org/plugins/igit-posts-slider-widget/" target="_blank">IGIT Posts Slider Widget</a>.</p>
<p style="text-align: justify;">It’s important to recognize that your theme or plugin may also use this script, even if it’s not listed in the disclosure. If you’ve ever lost an entire weekend fixing client sites that fell victim to TimThumb exploits, then you know that disabling the WebShot option is probably a good idea. This is a simple thing that you can do now to prevent your sites from getting hacked.</p>
<div id="better-author-bio-div">
<div class="better-author-bio-div-info"><img decoding="async" id="grav-d12f506a8f9afba443178608fc9e2232-0" class="avatar avatar-60 photo grav-hashed grav-hijack" src="https://1.gravatar.com/avatar/d12f506a8f9afba443178608fc9e2232?s=60&amp;d=&amp;r=R" alt="" width="60" height="60" /></p>
<h4 class="font-headlines" style="text-align: justify;">Who is Sarah Gooding</h4>
<p class="better-author-bio-div-meta" style="text-align: justify;">Sarah Gooding is an Editorial Ninja at Audrey Capital. When not writing about WordPress, she enjoys baking, knitting, judging beer competitions and spending time with her Italian Greyhound.</p>
</div>
</div>
</div>
<p>The post <a href="https://cvtfradio.net/2014/10/how-to-get-outstanding-urban-night-photographs/">New Zero-Day Vulnerability Discovered in TimThumb Script</a> appeared first on <a href="https://cvtfradio.net"></a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
