A zero-day vulnerability in the popular TimThumb plugin for WordPress leaves many websites vulnerable to exploits that allow unauthorized attackers to execute malicious code, security researchers have warned. The vulnerability, which was disclosed Tuesday on the Full Disclosure mailing list , affects WordPress sites that have TimThumb installed with the webshot option enabled. Fortunately, it is disabled by default, and sites that are hosted on WordPress.com are also not susceptible. Still, at press time, there was no patch for the remote-code execution hole. People who are unsure if their WordPress-enabled site is vulnerable should open the timthumb file inside their theme or plugin directory, search for the text string “WEBSHOT_ENABLED,” and ensure that it’s set to false. When “WEBSHOT_ENABLED” is set to true, attackers can create or delete files and execute a variety of other commands, Daniel Cid, CTO of security firm Sucuri, warned in a blog post published Thursday . He said uploading a file to a vulnerable site was possible using URLs such as the following, where a.txt was the file being created: Read 1 remaining paragraphs | Comments
View original post here:
Running WordPress? Got webshot enabled? Turn it off or you’re toast
An old MUNI bus in San Francisco is getting a second life with a noble cause. Outfitted with toilets and showers, Lava Mae ‘s refurbished bus will bring mobile bathrooms to homeless people around the city. The long-awaited bus will make its first rounds this weekend . Read more…
In some parts of the world a mosquito bite is a minor inconvenience that might result in a few days of uncomfortable itching. In other parts, though, the pests spread deadly diseases like malaria and dengue fever. So for the 2014 World Health Day, ad agency Leo Burnett created the world’s first mosquito-repelling newspaper in Sri Lanka. Read more…
Windows: Free image editor Paint.NET has released its first major update in six years. The new version packs a better rendering engine and a bunch of other improvements that still rank it as an essential Windows download . Read more…