• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

GeekyFaust

Technology News and Reviews Philippines

  • Home
  • About
    • Biography
  • Contact Us
  • News
    • Blog
    • Gaming
    • Reviews
    • Editorial
    • Laptops
    • Gadgets
    • Mobile
You are here: Home / Software / Secure your WordPress TimThump.php Vulnerability Attack

Secure your WordPress TimThump.php Vulnerability Attack

By Faust Principe September 4, 2011

There’s been a recent mass infection and attack in WordPress self-hosted blogs affecting the TimThumb.php, l10n.js, and WordPress core files in the “/wp-includes/js” folder.

While checking my rounds on geekyfaust.info the Avast Internet Security flagged my site infected with malware.

The TimThumb.php is used to resize thumbnail image/s plugins and templates using these features are not spared from the vulnerability.

This attack are used for blackhat seo purposes, some of my blog/s Alexa traffic traffic stumbled, update and replace the codes of your timthumb.php powered WordPress Templates right here.

Re-upload, replace new core files in “wp-includes” inside your WordPress root folder.

Check your blog by downloading this text file, upload it in your site/s root folder and rename sucuri_wp_check.txt to sucuri_wp_check.php

It will look like this “https://geekyfaust.info/sucuri_wp_check.txt rename it to https://geekyfaust.info/sucuri_wp_check.php”

Or you can individually scan your blog/s with this site check scanner

A yet and simple tool will check for possible intrusions or web injections in your site/s.

Credits:

Sucuri Blog

Tagged With: Blog, Blogs, malware, malware site check, Security, TimThump.php, Wordpress

About Faust Principe

Faust is the author and founder of GeekyFaust. You can follow him at facebook.com/geekyfaust don't forget to like and share!

Reader Interactions

Comments

  1. Philippines IT School says

    September 4, 2011 at 12:31 am

    Thanks for the tips Mr. Faust!!!

  2. Faust says

    September 4, 2011 at 9:54 am

    secure your sites now asap! 🙂

  3. Philippines IT School says

    September 4, 2011 at 8:55 pm

    lagi .. i’m trying to move away from WordPress to give way para sa among custom CMS 🙂 but thanks for the tips .. dagahan mag benefit ani 🙂

  4. Faust says

    September 5, 2011 at 10:36 pm

    that’s great! but how will you address the technical support needs of the custom cms?

  5. Dreb says

    September 10, 2011 at 12:17 pm

    Thanks for the great guide. One of my sites is infected with this kind of attack. Will try to implement the solution you’ve mentioned above (upload new copies of wp-includes files.)

    Ask lang po. What plugin or preventive measures that could be applied to avoid this kind of attack again?

    Thanks!

  6. Faust says

    September 11, 2011 at 11:25 am

    upload and install Theme Authenticity Checker (TAC) plugin directly from your dashboard wordpress plugin directory, check for any malware hacks by uploading and renaming wp_security_check.txt to wp_security_check.php and do some checks, install themes and plugins from a reputable source/s.

  7. Dr Jesus says

    September 24, 2011 at 2:39 pm

    Hirap niyan kapag madaming website mo ang gumagamit ng timthumb. Hirap iupdate isa isa. May bago ako napansin, sa gallery plugin naman, ginagamit para magupload ng executable file.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Primary Sidebar

Recent Stories

Creat8 joined forces with DOLE, ECOP, and EduCare to Launch INITIATE 2025: A Career & Education Congress

DOGE & SOL Sink in Today’s Correction—Savvy Investors Pivot to BTC Miner for Stable 7%+ Daily Yield

GameZone presents Super Divas: The Concert

Five Best Cloud Mining Platforms to Build Long-Term Wealth with Crypto

Trump’s Crypto Report White House: U.S. Eyes Golden Age of Digital Assets

Footer

CRYPTOCURRENCY

Small Bitcoin (BTC) Investors Actively Accumulate Cryptocurrency
Will Ripple (XRP) Be The Bitcoin (BTC)?
What are the biggest problems in Cryptocurrency?
Singapore May Introduce Further Cryptocurrency Restrictions
PayPal Is Finally Allowing Users To Move Their Cryptocurrency To Other Wallets

LATEST TECH STORIES

Oppo Top Stories
Telco Top Stories
Xiaomi Top Stories
Epson Top Stories
Secretlab Top Stories
Lenovo Top Stories
Android Top Stories

Editor’s Choice

Free browser games to play to make your day productive
Best Solitaire Classic Games to Play for Free
The best free online money games your kids will love
The best online calculator for reduced mortgage payments
The best car payment calculator for auto buyers
Best Free Online Math Games to Play for Students
Guide to reloading phone numbers of relatives in the Philippines
Customer Care Outsourcing – Shared Or Offshore?
How to settle bad credit loans and be debt free

POPULAR TOPICS

Mobile Phone / Smartphone
Latest News
Tech Reviews
How To's
Guides
Tech Gadgets
Local Telco
Computer Hardware
Software & Apps
Gaming

TRENDING POST

How to activate and register DITO SIM
How to apply for BDO Teacher Salary Loan
How to register and activate Veterans Bank ATM Online Banking
How to apply for Teacher Loans at China Bank Savings
PS Bank Online E-Banking
UnionBank Send and Receive Funds Online
How to apply for a EastWest Bank Teacher Loan

TOP MOBILE BRANDS

Asus AOC Black Shark Epson Fujitsu Sony Xiaomi Apple Nokia Cherry Mobile Oppo ZTE MyPhone Cloudfone Lenovo Samsung Secretlab Motorola Huawei LG Xperia MediaTek Vivo Klevv

GeekyFaust | Philippines Tech News & Reviews Copyright © 2026