<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tech Guy Kevin &#187; Tech News</title>
	<atom:link href="http://techguykevin.com/category/tech-news/feed/" rel="self" type="application/rss+xml" />
	<link>http://techguykevin.com</link>
	<description>I&#039;m working on it...</description>
	<lastBuildDate>Mon, 16 Jan 2012 17:41:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>WordPress Security Issue with timthumb</title>
		<link>http://techguykevin.com/wordpress-timthumb-hac/</link>
		<comments>http://techguykevin.com/wordpress-timthumb-hac/#comments</comments>
		<pubDate>Wed, 03 Aug 2011 17:36:13 +0000</pubDate>
		<dc:creator>techguykevin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Tech News]]></category>

		<guid isPermaLink="false">http://techguykevin.com/?p=27</guid>
		<description><![CDATA[Thousands of websites are at risk of being compromised due to critical vulnerability in a popular third-party image manipulation script called timthumb. The image utility is not part of the WordPress core files, but is used in hundreds of WordPress &#8230; <a href="http://techguykevin.com/wordpress-timthumb-hac/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Thousands of websites are at risk of being compromised due to critical vulnerability in a popular third-party image manipulation script called timthumb.</p>
<p>The image utility is not part of the WordPress core files, but is used in hundreds of WordPress themes. The script consists of a single file called timthumb.php and provides on-the-fly image cropping, zooming and resizing. Timthumb relies a white list of domain names from which images can be remotely fetched, which include popular image hosting web sites like Flickr, Picasa, Blogger, WordPress and many more.</p>
<p>There is a flaw in the validation process which allows files to be loaded from domains like &#8216;wordpress.com.evilhacker.cn&#8217; because wordpress.com is in the domain name.</p>
<p>The script stores these images in a cache directory which is web accessible to make the script work on most servers without needing to be modified.</p>
<p>The timthumb developers are already working on a <a href="http://code.google.com/p/timthumb/issues/detail?id=212" title="timthumb vulnerability">fix</a>.  </p>
<p>The problem I see here is that many of the people who are at risk (the ones that use WordPress because it&#8217;s &#8216;easy&#8217;) don&#8217;t even know they are vulnerable let alone how to replace the file.</p>
]]></content:encoded>
			<wfw:commentRss>http://techguykevin.com/wordpress-timthumb-hac/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Served from: techguykevin.com @ 2012-05-20 11:09:02 -->
