<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.0.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>My Site My Way Support &#124; Topic: Security risk in echelon theme</title>
		<link>http://mysitemyway.com/support/topic/security-risk-in-echelon-theme</link>
		<description>My Site My Way Support | Topic: Security risk in echelon theme</description>
		<language>en-US</language>
		<pubDate>Tue, 21 May 2013 17:23:10 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.0.2</generator>
		<textInput>
			<title><![CDATA[Search]]></title>
			<description><![CDATA[Search all topics from these forums.]]></description>
			<name>q</name>
			<link>http://mysitemyway.com/support/search.php</link>
		</textInput>
		<atom:link href="http://mysitemyway.com/support/rss/topic/security-risk-in-echelon-theme" rel="self" type="application/rss+xml" />

		<item>
			<title>Elliott on "Security risk in echelon theme"</title>
			<link>http://mysitemyway.com/support/topic/security-risk-in-echelon-theme#post-57920</link>
			<pubDate>Thu, 15 Mar 2012 13:18:19 +0000</pubDate>
			<dc:creator>Elliott</dc:creator>
			<guid isPermaLink="false">57920@http://mysitemyway.com/support/</guid>
			<description>&#60;p&#62;Hello tannera0,&#60;/p&#62;
&#60;p&#62;You need to update your theme to the latest version.  It's always best to keep Wordpress, plugins, and themes updated.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>tannera0 on "Security risk in echelon theme"</title>
			<link>http://mysitemyway.com/support/topic/security-risk-in-echelon-theme#post-57898</link>
			<pubDate>Thu, 15 Mar 2012 12:33:58 +0000</pubDate>
			<dc:creator>tannera0</dc:creator>
			<guid isPermaLink="false">57898@http://mysitemyway.com/support/</guid>
			<description>&#60;p&#62;I got this email from my bluehost hoster.&#60;br /&#62;
&#34;Dear customer,&#60;/p&#62;
&#60;p&#62;This is a courtesy notice that we have found and corrected exploitable timthumb.php file(s) on your account, which are listed below.  While we have corrected these files, we do recommend you ensure all potential exploits are corrected on your account.  This is best done by updating all scripts, plugins, modules and themes on your account to the latest version.&#60;/p&#62;
&#60;p&#62;The timthumb.php file is a script commonly used in WordPress's (and other software's) themes and plugins to resize images. The exploit allows an attacker to arbitrarily upload and create files and/or folders on your account, which can then be used for a number of malicious tasks, including but not limited to defacement, browser high-jacking and infection, data harvesting and more.  After a site has been exploited, it may lead to becoming labeled a &#34;Malicious Website&#34; by Google or other security authorities.&#60;/p&#62;
&#60;p&#62;Any timthumb.php file below version 1.35, but above version 1.09 is considered vulnerable, unless patched. To prevent being compromised, we advise you update all instances of timthumb.php to version 2.0, or patch the existing vulnerable files.  Note that patching the files requires more in-depth knowledge of the PHP scripting language.&#60;/p&#62;
&#60;p&#62;The updated version of timthumb.php can be found here:&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://timthumb.googlecode.com/svn/trunk/timthumb.php&#34; rel=&#34;nofollow&#34;&#62;http://timthumb.googlecode.com/svn/trunk/timthumb.php&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;We have automatically patched the following files for you:&#60;/p&#62;
&#60;p&#62;       /home1/website/public_html/wp-content/themes/echelon/lib/scripts/thumb.php&#60;/p&#62;
&#60;p&#62;Additional information regarding the compromise can be found at the following two websites, as well as others; note that all external websites in this email are not affiliated with Bluehost.com in any capacity, and are for your reference only.&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://markmaunder.com/2011/08/01/zero-day-vulnerability-in-many-wordpress-themes/&#34; rel=&#34;nofollow&#34;&#62;http://markmaunder.com/2011/08/01/zero-day-vulnerability-in-many-wordpress-themes/&#60;/a&#62;&#60;br /&#62;
&#60;a href=&#34;http://redleg-redleg.blogspot.com/2011/08/malware-hosted-newportalsecom.html&#34; rel=&#34;nofollow&#34;&#62;http://redleg-redleg.blogspot.com/2011/08/malware-hosted-newportalsecom.html&#60;/a&#62;&#34;&#60;/p&#62;
&#60;p&#62;What should I do?
&#60;/p&#62;</description>
		</item>

	</channel>
</rss>
