<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: TimThumb Security Vulnerability &#8211; Common in WordPress Themes</title>
	<atom:link href="http://www.themelab.com/2011/08/02/timthumb-security-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.themelab.com/2011/08/02/timthumb-security-exploit/</link>
	<description></description>
	<lastBuildDate>Tue, 19 Mar 2013 01:28:15 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Leland</title>
		<link>http://www.themelab.com/2011/08/02/timthumb-security-exploit/#comment-17642</link>
		<dc:creator>Leland</dc:creator>
		<pubDate>Sun, 07 Aug 2011 00:18:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.themelab.com/?p=2760#comment-17642</guid>
		<description><![CDATA[I think that&#039;s one of the reasons why Mark Maunder described TimThumb as &quot;inherently insecure.&quot;]]></description>
		<content:encoded><![CDATA[<p>I think that&#8217;s one of the reasons why Mark Maunder described TimThumb as &#8220;inherently insecure.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marie-Aude</title>
		<link>http://www.themelab.com/2011/08/02/timthumb-security-exploit/#comment-17637</link>
		<dc:creator>Marie-Aude</dc:creator>
		<pubDate>Fri, 05 Aug 2011 20:38:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.themelab.com/?p=2760#comment-17637</guid>
		<description><![CDATA[One of the other issues with TimThumb is that it requires a chmod 777 to properly function. I never felt confident with that.]]></description>
		<content:encoded><![CDATA[<p>One of the other issues with TimThumb is that it requires a chmod 777 to properly function. I never felt confident with that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Leland</title>
		<link>http://www.themelab.com/2011/08/02/timthumb-security-exploit/#comment-17620</link>
		<dc:creator>Leland</dc:creator>
		<pubDate>Wed, 03 Aug 2011 22:05:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.themelab.com/?p=2760#comment-17620</guid>
		<description><![CDATA[Yep, hopefully they&#039;ll get the message and update their scripts.]]></description>
		<content:encoded><![CDATA[<p>Yep, hopefully they&#8217;ll get the message and update their scripts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Leland</title>
		<link>http://www.themelab.com/2011/08/02/timthumb-security-exploit/#comment-17619</link>
		<dc:creator>Leland</dc:creator>
		<pubDate>Wed, 03 Aug 2011 22:05:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.themelab.com/?p=2760#comment-17619</guid>
		<description><![CDATA[Hey Darren, thanks for stopping by and sharing your thoughts about this.

Definitely interesting to hear from one of the original creators of the timthumb script.]]></description>
		<content:encoded><![CDATA[<p>Hey Darren, thanks for stopping by and sharing your thoughts about this.</p>
<p>Definitely interesting to hear from one of the original creators of the timthumb script.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Leland</title>
		<link>http://www.themelab.com/2011/08/02/timthumb-security-exploit/#comment-17617</link>
		<dc:creator>Leland</dc:creator>
		<pubDate>Wed, 03 Aug 2011 20:41:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.themelab.com/?p=2760#comment-17617</guid>
		<description><![CDATA[Yep, as far as a quick fix you can just include the latest timthumb script without the allowed sites.

If you have more time, maybe utilize the &lt;code&gt;add_image_size&lt;/code&gt; so it takes advantage of WordPress&#039; APIs.]]></description>
		<content:encoded><![CDATA[<p>Yep, as far as a quick fix you can just include the latest timthumb script without the allowed sites.</p>
<p>If you have more time, maybe utilize the <code>add_image_size</code> so it takes advantage of WordPress&#8217; APIs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Leland</title>
		<link>http://www.themelab.com/2011/08/02/timthumb-security-exploit/#comment-17616</link>
		<dc:creator>Leland</dc:creator>
		<pubDate>Wed, 03 Aug 2011 20:40:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.themelab.com/?p=2760#comment-17616</guid>
		<description><![CDATA[Hey Andreas, definitely a good point about having a built-in update capability.

You could say the same thing about the framework-&gt;child theme model so you can safely upgrade the &quot;core&quot; theme without sacrificing any of your modifications (done in the child theme).]]></description>
		<content:encoded><![CDATA[<p>Hey Andreas, definitely a good point about having a built-in update capability.</p>
<p>You could say the same thing about the framework->child theme model so you can safely upgrade the &#8220;core&#8221; theme without sacrificing any of your modifications (done in the child theme).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Leland</title>
		<link>http://www.themelab.com/2011/08/02/timthumb-security-exploit/#comment-17615</link>
		<dc:creator>Leland</dc:creator>
		<pubDate>Wed, 03 Aug 2011 20:38:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.themelab.com/?p=2760#comment-17615</guid>
		<description><![CDATA[They weren&#039;t stripped, just didn&#039;t have any blockquote styles for comments until now. :)

Also couldn&#039;t agree more with your comment. It really bothered me how someone who has contributed so much was just getting ripped to shreds because of this.]]></description>
		<content:encoded><![CDATA[<p>They weren&#8217;t stripped, just didn&#8217;t have any blockquote styles for comments until now. <img src='http://www.themelab.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Also couldn&#8217;t agree more with your comment. It really bothered me how someone who has contributed so much was just getting ripped to shreds because of this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Leland</title>
		<link>http://www.themelab.com/2011/08/02/timthumb-security-exploit/#comment-17614</link>
		<dc:creator>Leland</dc:creator>
		<pubDate>Wed, 03 Aug 2011 20:33:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.themelab.com/?p=2760#comment-17614</guid>
		<description><![CDATA[Yep, I noticed they posted about no longer using the timthumb script in the latest versions of their themes. http://www.elegantthemes.com/blog/theme-changesbug-fixes/timthumb-vulnerability-security-update]]></description>
		<content:encoded><![CDATA[<p>Yep, I noticed they posted about no longer using the timthumb script in the latest versions of their themes. <a href="http://www.elegantthemes.com/blog/theme-changesbug-fixes/timthumb-vulnerability-security-update" rel="nofollow">http://www.elegantthemes.com/blog/theme-changesbug-fixes/timthumb-vulnerability-security-update</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Len</title>
		<link>http://www.themelab.com/2011/08/02/timthumb-security-exploit/#comment-17612</link>
		<dc:creator>Len</dc:creator>
		<pubDate>Wed, 03 Aug 2011 16:38:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.themelab.com/?p=2760#comment-17612</guid>
		<description><![CDATA[Hmmm, I meant for the 1st paragraph in my comment above to be wrapped in blockquote tags. For some reason they were stripped out. It was supposed to indicate me quoting from your post but now looks like I am plagiarising your post. :)]]></description>
		<content:encoded><![CDATA[<p>Hmmm, I meant for the 1st paragraph in my comment above to be wrapped in blockquote tags. For some reason they were stripped out. It was supposed to indicate me quoting from your post but now looks like I am plagiarising your post. <img src='http://www.themelab.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Len</title>
		<link>http://www.themelab.com/2011/08/02/timthumb-security-exploit/#comment-17611</link>
		<dc:creator>Len</dc:creator>
		<pubDate>Wed, 03 Aug 2011 16:34:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.themelab.com/?p=2760#comment-17611</guid>
		<description><![CDATA[&lt;blockquote&gt;I noticed that the TimThumb developer, Ben Gillbanks, was getting directly and indirectly &quot;bashed&quot; pretty hard in the comments of the original vulnerability post.&lt;/blockquote&gt;

Yeah, and there is no call for that. Ben has given so much of himself to the WordPress community. A vulnerability was discovered and was quickly fixed.

Non-coders don&#039;t seem to understand the complexities involved in writing code. You think you have a solid airtight snippet and then comes along some hacker with way too much time on his hands poking and prodding until he finds something.

Those of us who are active in the WordPress community know of Ben&#039;s tireless contributions.]]></description>
		<content:encoded><![CDATA[<blockquote><p>I noticed that the TimThumb developer, Ben Gillbanks, was getting directly and indirectly &#8220;bashed&#8221; pretty hard in the comments of the original vulnerability post.</p></blockquote>
<p>Yeah, and there is no call for that. Ben has given so much of himself to the WordPress community. A vulnerability was discovered and was quickly fixed.</p>
<p>Non-coders don&#8217;t seem to understand the complexities involved in writing code. You think you have a solid airtight snippet and then comes along some hacker with way too much time on his hands poking and prodding until he finds something.</p>
<p>Those of us who are active in the WordPress community know of Ben&#8217;s tireless contributions.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic page generated in 0.303 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2013-05-02 08:35:28 -->
