thumbs.php and the 'timbthumb' vulnerability

Discussion regarding Joomla! 2.5 security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Locked
jasonatextreme
Joomla! Fledgling
Joomla! Fledgling
Posts: 1
Joined: Fri Oct 21, 2011 3:00 am

thumbs.php and the 'timbthumb' vulnerability

Post by jasonatextreme » Fri Oct 21, 2011 3:11 am

I have a 1.7 site that has been hacked and is showing signs of the 'timthumb.php' vulnerability that I can found elsewhere on the internet. Several folders containing a 'thumbs.php' file have been found, whcih appear to be able to execute an arbitrary script, however I can't find any evvidence of a "timthumb.php" ever being present in our installation.

Below are a set of files I know have been modified because of the hack. I have restored these from earlier backups. Does any one know if these modifications are a symptom of a particular hack? Note that the "thumbs.php" php files were found in "logs", "cache" and "tmp"

./public_html/templates/themza_j15_23/component.php
./public_html/templates/themza_j15_23/index.php
./public_html/templates/rhuk_milkyway/component.php
./public_html/templates/rhuk_milkyway/index.php
./public_html/templates/beez_20/error.php
./public_html/templates/beez_20/component.php
./public_html/templates/beez_20/index.php
./public_html/templates/ja_purity/component.php
./public_html/templates/ja_purity/index.php
./public_html/templates/atomic/error.php
./public_html/templates/atomic/component.php
./public_html/templates/atomic/index.php
./public_html/templates/beez5/error.php
./public_html/templates/beez5/component.php
./public_html/templates/beez5/index.php
./public_html/templates/system/offline.php
./public_html/templates/system/error.php
./public_html/templates/system/component.php
./public_html/includes/defines.php
./public_html/libraries/joomla/application/component/view.php
./public_html/libraries/joomla/application/component/controller.php
./public_html/libraries/joomla/import.php
./public_html/logs
./public_html/cache
./public_html/tmp

Please let me know if you need further info.
Jason

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: thumbs.php and the 'timbthumb' vulnerability

Post by mandville » Fri Oct 21, 2011 5:59 am

the problem with timthumb is that it is included with a lot of extensions and modules.
a quick search of the forums will show how "vulnerable" it is/was
see mainly
http://forum.joomla.org/viewtopic.php?f=432&t=662962
http://code.google.com/p/timthumb/issue ... ?id=273#c2
http://code.google.com/p/timthumb/issue ... ?id=274#c1
http://www.binarymoon.co.uk/2011/08/tim ... FeedBurner

follow checklist7, safe route to recovery
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}


Locked

Return to “Security in Joomla! 2.5”