why didnt he upgrade your timthumb.php ?
the upgraded version is pretty secure imho.
just replace old timthumb.php with new one. problem solved.
edit: looks like timthumb is no more maintained.
here is alternative
https://github.com/mindsharelabs/mthumb