Ask the community

This is a community support forum where you can ask
questions and interact with other PremiumPress Customers.

Sucuri and DirectoryPress

  • Tony
    Tony
    Newbie 20 points
    July 4, 2013 at 7:30 pm

    Sorry if this has been covered but I can’t search the old forum.

    I am using the Sucuri plugin with Directory press 1.7.4. I have two quick questions:

    1. Does Directory Press use TimThumb or similar scripts?

    2. Sucuri wants to block direct PHP access to any file inside wp-includes. Is this ok to do with DirectoryPress?

    Thanks, Tony

    I am

  • Shakib
    Shakib
    Newbie 41 points
    July 4, 2013 at 8:07 pm

    Hi,
    1. DP is using TimThumb script in advanced-recent-posts plugin (can be found in the Widget Area)
    2. You might face some issues here.

    tip: backup your whole wp directory+dp, your database and try using Sucuri with direct PHP access block level.

  • Richard Bonk
    Richard Bonk
    Super Guru 2,739 points
    July 4, 2013 at 8:38 pm

    As far as I know, DirectoryPress does not use TimThumb. It uses its own image resizing function which can be found in class_image.php

    @Shakib, can you tell me where did you find any reference to timthumb?

  • Shakib
    Shakib
    Newbie 41 points
    July 4, 2013 at 10:04 pm

    plugins\advanced-recent-posts-widget\advanced-recent-posts-widget.php

    Attachments:
    You must be logged in to view attached files.
  • Mark Fail
    Mark Fail
    Super Guru 12,821 points
    July 5, 2013 at 2:42 am

    There hasnt been any TimThumbs for along time now, the above file isnt part of our themes, looks like a plugin.

  • Tony
    Tony
    Newbie 20 points
    July 5, 2013 at 3:33 am

    Thanks, I ran a scan using the plugin Tim Thumb Vulnerability Scanner and it came up with no Tim Thumbs in the theme so this supports what Mark is saying.

    How about blocking PhP access to any file in WP-includes???

  • Mark Fail
    Mark Fail
    Super Guru 12,821 points
    July 7, 2013 at 10:26 am

    you might find WordPres needs access to some of those files.

Viewing 7 posts - 1 through 7 (of 7 total)