How to Handle Wordpress TimThumb Exploit Attack

This morning around 9 AM i've been shocked with brutal attack at one of my wordpress blog. Fortunately i've been using wordpress firewall 2 to prevent any further damage. The plugin has been blocked more than 350 attack within 2 hours from the same ip, this incident were immediately known because wordpress firewall 2 plugin also sent alert notification to my email address.

First i get panic because in the hosting i've used were not just holding one wordpress blog, it contains more than twenty blogs. How could i manage to handle such attack while i'm still driving on my Toyota Avansa, all i have just Gemini Curve 9300 Blackberry. Soon after i arrive to my friend's home i carefully read the alert notification :

First, i managed to access my cpanel hosting through my curve 9300 then i add the source ip as blocked and blacklisted. Then to make sure that there is nothing wrong with the attacked blog i decide to reinstall the wordpress it self. After that i'm tracing the ip used for sending this evil exploit attack, i've been redirected to arin.net page showing details on that ip. The ip was from United States and came from bluehost.com.

So after 5 minutes triple read all the information i found four email address for reporting the abuse :
- support-tos@bluehost.com
- abuse@tinet.net
- abuse@level3.com
- abuse@bluehost.com

Several hours later, while i'm writing this article, i also got reply from other email address, asking if the attack still on going. Thanks God, for this awesome morning :D
































