<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.0.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Support Forum - Topic: Timthumb Vulnerability on Habitat</title>
		<link>http://www.kriesi.at/support/topic/timthumb-vulnerability-on-habitat</link>
		<description>Support Forum - Topic: Timthumb Vulnerability on Habitat</description>
		<language>en-US</language>
		<pubDate>Wed, 22 May 2013 22:26:32 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.0.2</generator>
		<textInput>
			<title><![CDATA[Search]]></title>
			<description><![CDATA[Search all topics from these forums.]]></description>
			<name>q</name>
			<link>http://www.kriesi.at/support/search.php</link>
		</textInput>
		<atom:link href="http://www.kriesi.at/support/rss/topic/timthumb-vulnerability-on-habitat" rel="self" type="application/rss+xml" />

		<item>
			<title>Dude on "Timthumb Vulnerability on Habitat"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-vulnerability-on-habitat#post-30402</link>
			<pubDate>Tue, 25 Oct 2011 07:08:37 +0000</pubDate>
			<dc:creator>Dude</dc:creator>
			<guid isPermaLink="false">30402@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;You can delete timthumb.php for Newscast (if you're using the latest theme version). As fas as I know Display requires timthumb but the latest theme version (v.2.0.3) comes with the updated timthumb script which is secure.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>ktaylor on "Timthumb Vulnerability on Habitat"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-vulnerability-on-habitat#post-30386</link>
			<pubDate>Mon, 24 Oct 2011 21:32:08 +0000</pubDate>
			<dc:creator>ktaylor</dc:creator>
			<guid isPermaLink="false">30386@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hi,&#60;br /&#62;
Our site has recently been hacked.  Can I confirm with you that I can simply delete the timthumb.php file and this wont break anything? I am using Display and Newscast.&#60;/p&#62;
&#60;p&#62;Thanks!
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Chris Beard on "Timthumb Vulnerability on Habitat"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-vulnerability-on-habitat#post-27897</link>
			<pubDate>Mon, 26 Sep 2011 20:28:21 +0000</pubDate>
			<dc:creator>Chris Beard</dc:creator>
			<guid isPermaLink="false">27897@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Thanks for letting us know, I'll contact Kriesi about it.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>mediaplana on "Timthumb Vulnerability on Habitat"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-vulnerability-on-habitat#post-27864</link>
			<pubDate>Mon, 26 Sep 2011 14:21:54 +0000</pubDate>
			<dc:creator>mediaplana</dc:creator>
			<guid isPermaLink="false">27864@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;hej guys, just to let you know. the timthumb.php is still in the theme version on themeforest and it is definitly the old and hacked version last updated on 17th of march 2011 - before the fix. please update asap.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Kriesi on "Timthumb Vulnerability on Habitat"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-vulnerability-on-habitat#post-26325</link>
			<pubDate>Sat, 03 Sep 2011 08:16:16 +0000</pubDate>
			<dc:creator>Kriesi</dc:creator>
			<guid isPermaLink="false">26325@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hey! Habitat no longer uses the timthumb script, it instead relies on the natural wordpress resizing. I would suggest to simply delete it from the theme folder. I will release an update for the themes that dont rely on it but have a copy of the file in the theme folder next week ;)
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Chris Beard on "Timthumb Vulnerability on Habitat"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-vulnerability-on-habitat#post-26282</link>
			<pubDate>Fri, 02 Sep 2011 12:43:08 +0000</pubDate>
			<dc:creator>Chris Beard</dc:creator>
			<guid isPermaLink="false">26282@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hey,&#60;br /&#62;
sorry about that - I must have mislooked at the dates of all the recently updated files. Recently a timthumb vulnerability has come up and it has been patched, it seems it wasn't for habitat. I'll mail Kriesi about the fix.&#60;br /&#62;
Again exuse me for the delay/misinformation.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>martybuckenmeyer on "Timthumb Vulnerability on Habitat"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-vulnerability-on-habitat#post-26178</link>
			<pubDate>Thu, 01 Sep 2011 04:11:26 +0000</pubDate>
			<dc:creator>martybuckenmeyer</dc:creator>
			<guid isPermaLink="false">26178@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;BTW, when  I download the 'previously purchased,' theme, the files are identical to what I purchased in May...including the .rtf file.  So it looks like maybe it hasn't been updated recently?
&#60;/p&#62;</description>
		</item>
		<item>
			<title>martybuckenmeyer on "Timthumb Vulnerability on Habitat"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-vulnerability-on-habitat#post-26177</link>
			<pubDate>Thu, 01 Sep 2011 03:56:43 +0000</pubDate>
			<dc:creator>martybuckenmeyer</dc:creator>
			<guid isPermaLink="false">26177@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Well, for the time-being then, I guess this is an issue for me to figure out with Themeforest, because I don't see any option on that site to download an 'update.'  My only options appear to be downloading the old theme or purchasing the theme.  There is no 'update' indicated anywhere...Can you verify that there is, in fact, an update there?&#60;/p&#62;
&#60;p&#62;When I figure this first step out, I'll come back.   Thanks.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Chris Beard on "Timthumb Vulnerability on Habitat"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-vulnerability-on-habitat#post-26158</link>
			<pubDate>Wed, 31 Aug 2011 20:57:55 +0000</pubDate>
			<dc:creator>Chris Beard</dc:creator>
			<guid isPermaLink="false">26158@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;No, all updates are free.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>martybuckenmeyer on "Timthumb Vulnerability on Habitat"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-vulnerability-on-habitat#post-26082</link>
			<pubDate>Tue, 30 Aug 2011 03:02:49 +0000</pubDate>
			<dc:creator>martybuckenmeyer</dc:creator>
			<guid isPermaLink="false">26082@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Will I have to &#34;purchase&#34; the theme again?
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Chris Beard on "Timthumb Vulnerability on Habitat"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-vulnerability-on-habitat#post-26062</link>
			<pubDate>Mon, 29 Aug 2011 21:35:25 +0000</pubDate>
			<dc:creator>Chris Beard</dc:creator>
			<guid isPermaLink="false">26062@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;When you download the updated version there's a version.rtf file which tells you what has been updated so you can replace the files in question. However, you can just replace the entire theme without your settings being lost since they're stored in the database.. which remains untouched.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>martybuckenmeyer on "Timthumb Vulnerability on Habitat"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-vulnerability-on-habitat#post-26034</link>
			<pubDate>Mon, 29 Aug 2011 16:48:26 +0000</pubDate>
			<dc:creator>martybuckenmeyer</dc:creator>
			<guid isPermaLink="false">26034@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;I purchased in May 2011; I think I'm running version 1.1.1.  To update, do I just download the 'current' theme from Themeforest and replace the theme on Wordpress?  Will I have to rebuild the site again?
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Chris Beard on "Timthumb Vulnerability on Habitat"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-vulnerability-on-habitat#post-26009</link>
			<pubDate>Mon, 29 Aug 2011 10:54:24 +0000</pubDate>
			<dc:creator>Chris Beard</dc:creator>
			<guid isPermaLink="false">26009@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hi,&#60;br /&#62;
are you running the latest version of the theme? Kriesi released a timthumb update just a few days ago. The update can be downloaded on themeforest.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>martybuckenmeyer on "Timthumb Vulnerability on Habitat"</title>
			<link>http://www.kriesi.at/support/topic/timthumb-vulnerability-on-habitat#post-25941</link>
			<pubDate>Sat, 27 Aug 2011 03:28:48 +0000</pubDate>
			<dc:creator>martybuckenmeyer</dc:creator>
			<guid isPermaLink="false">25941@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Just received a message from my web host about timthumb.php vulnerability. Is there something that Habitat users need to do to patch or update our sites?  I am a definite newbie when it comes to messing with the base code, btw.
&#60;/p&#62;</description>
		</item>

	</channel>
</rss>
