<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket Query</title>
    <link>http://localhost:8080/trac/query?status=closed&amp;component=Parrot+server&amp;milestone=Maintenance&amp;group=resolution&amp;desc=1&amp;order=summary</link>
    <description>Support and issues tracking for the Transition Network Web Project.</description>
    <language>en-US</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/query?status=closed&amp;component=Parrot+server&amp;milestone=Maintenance&amp;group=resolution&amp;desc=1&amp;order=summary</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
        <link>http://localhost:8080/trac/ticket/583</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/583</guid>
        <title>#583: tmp files on parrot exceeded inode limit</title>
        <pubDate>Mon, 02 Sep 2013 12:28:46 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Users are attempting to purchase a DVD and the cart always zeros out even after attempts to update cart etc.
&lt;/p&gt;
&lt;p&gt;
Laura suggests that this may be a server issue and to start with Chris:
&lt;/p&gt;
&lt;p&gt;
The prob could v likely be on the hosting side, so be worth contacting Chris first (and mention can add to cart all okay when logged in, view cart and alter and get to billing page, so could be a session setting that's changed) -
&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;Does the server have disk space left on /tmp. Session data is most likely written there. (sometimes this cart faff issue can happen because of that.)
&lt;/li&gt;&lt;/ol&gt;&lt;ol start="2"&gt;&lt;li&gt;Are the PHP Session settings correct/ have they changed recently? Chris can fix this if needing a tweakette in php.ini or other places in the underworld of those types of files.
&lt;/li&gt;&lt;/ol&gt;&lt;ol start="3"&gt;&lt;li&gt;DB could potentially need check/repair.
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
Another one is the shop element relies on cookies so if a user has set browser to not accept cookies may poss not work! (but think thats something not to think about here, as I tested as both logged in and logged out with cookies set to work on my browser, logged out got the 'cart empty' faff factor like other users will be getting.)
&lt;/p&gt;
&lt;p&gt;
If Chris can't spot the bug (does sound server side and sessions related from a quick test here, haven't looked at the server logs, but if get a mo later will see if I can), poss good to chat and I can think some more on it, but first thoughts alert me mostly to server side, sometimes a roll back to php 5.2 clicks things back into place (but shouldn't be needed).  Be good to see if there is a correlation with any server changes/tweaks happening around same timing that the cart stopped working.  Keep me in the loop if it is a server fix-y thing as always interested to hear results on bug fixing on sites.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/583#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/778</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/778</guid>
        <title>#778: need access to Parrot</title>
        <pubDate>Wed, 27 Aug 2014 12:16:39 GMT</pubDate>
        
        <dc:creator>annesley</dc:creator>

        <description>&lt;p&gt;
i need a publicly available &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; demo install to play with. should this be on Parrot? what (sub)domain can i use?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/778#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/538</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/538</guid>
        <title>#538: intransitionmovie.com checks and updates</title>
        <pubDate>Tue, 30 Apr 2013 20:02:03 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
The &lt;a class="ext-link" href="http://www.intransitionmovie.com/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.intransitionmovie.com/&lt;/a&gt; site has been migrated to &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;wiki:ParrotServer&lt;/a&gt;, the DNS might not have yet updated for everybody.
&lt;/p&gt;
&lt;p&gt;
Laura -- could you check that the site is working OK if you get a chance, especially the ecommerce elements?
&lt;/p&gt;
&lt;p&gt;
There are some outstanding updates, &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; is version 3.3.2 need updating to 3.5.1 and there are 12 plugins with updates available:
&lt;/p&gt;
&lt;pre class="wiki"&gt;18 installed plugins:
 UA affiliates
 UA affiliates-woocommerce-light
 UA akismet
  A backupwordpress
 UI bad-behavior
 UA bwp-minify
  A contact-form-7
 UA event-o-matic
  A transposh-translation-filter-for-wordpress
 UA usernoise
  A woocommerce
 UA woocommerce-export-csv
  A woocommerce-currency-converter
 UA woocommerce-dynamic-pricing
  A woocommerce-delivery-notes
 UA woocommerce-shipping-table-rate
 UA wp-customer-reviews
 UI wp-super-cache
Legend: A = Active, I = Inactive, U = Update Available
&lt;/pre&gt;&lt;p&gt;
I'm happy to do all these updates but I wouldn't know what exactly to check to see that the updates don't break anything -- would Laura be able to help with a quick check that updates haven't broken anything?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/538#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/811</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/811</guid>
        <title>#811: WordPress critical security release</title>
        <pubDate>Thu, 20 Nov 2014 20:25:07 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
From &lt;a class="ext-link" href="https://wordpress.org/news/2014/11/wordpress-4-0-1/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;the blog&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
&lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; 4.0.1 is now available. This is a critical security release for all previous versions and we strongly encourage you to update your sites immediately.
&lt;/p&gt;
&lt;p&gt;
Sites that support automatic background updates will be updated to &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; 4.0.1 within the next few hours. If you are still on &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; 3.9.2, 3.8.4, or 3.7.4, you will be updated to 3.9.3, 3.8.5, or 3.7.5 to keep everything secure. (We don’t support older versions, so please update to 4.0.1 for the latest and greatest.)
&lt;/p&gt;
&lt;p&gt;
&lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; versions 3.9.2 and earlier are affected by a critical cross-site scripting vulnerability, which could enable anonymous users to compromise a site.
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/811#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/594</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/594</guid>
        <title>#594: WordPress 3.6.1 Maintenance and Security Release</title>
        <pubDate>Wed, 11 Sep 2013 22:05:01 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
The following is from &lt;a class="ext-link" href="http://wordpress.org/news/2013/09/wordpress-3-6-1/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://wordpress.org/news/2013/09/wordpress-3-6-1/&lt;/a&gt;
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
&lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; 3.6.1 is also a security release for all previous &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; versions and we strongly encourage you to update your sites immediately. It addresses three issues fixed by the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; security team:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Block unsafe PHP unserialization that could occur in limited situations and setups, which can lead to remote code execution. Reported by Tom Van Goethem.
&lt;/li&gt;&lt;li&gt;Prevent a user with an Author role, using a specially crafted request, from being able to create a post “written by” another user. Reported by Anakorn Kyavatanakij.
&lt;/li&gt;&lt;li&gt;Fix insufficient input validation that could result in redirecting or leading a user to another website. Reported by Dave Cummo, a Northrup Grumman subcontractor for the U.S. Centers for Disease Control and Prevention.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Additionally, we’ve adjusted security restrictions around file uploads to mitigate the potential for cross-site scripting.
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/594#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/699</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/699</guid>
        <title>#699: Update Core &amp; Plugins on transitionculture.org</title>
        <pubDate>Mon, 10 Mar 2014 11:46:33 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
This site needs an update.
&lt;/p&gt;
&lt;p&gt;
I'll do a database backup then update it.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/699#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/550</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/550</guid>
        <title>#550: Transition Town Totnes migration</title>
        <pubDate>Sun, 19 May 2013 14:59:44 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
It has been agreed to migrate Transition Town Totnes, &lt;a class="ext-link" href="http://transitiontowntotnes.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://transitiontowntotnes.org/&lt;/a&gt; to &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;wiki:ParrotServer&lt;/a&gt; and this ticket has been created to record this process and the time spent on it and the documentation of the migration.
&lt;/p&gt;
&lt;p&gt;
There is also an issue regarding what, if anything, to do with the old Drupal site at &lt;a class="ext-link" href="http://archive.transitiontowntotnes.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://archive.transitiontowntotnes.org/&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/550#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/577</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/577</guid>
        <title>#577: Transition Streets Wordpress Migration</title>
        <pubDate>Tue, 06 Aug 2013 21:28:25 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
This is a ticket to document the migration of the Transition Totnes &lt;a class="ext-link" href="http://www.transitionstreets.org.uk/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.transitionstreets.org.uk/&lt;/a&gt; &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;wiki:WordPress&lt;/a&gt; site to &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;wiki:ParrotServer&lt;/a&gt;.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/577#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/656</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/656</guid>
        <title>#656: Spam being sent out via Transition Culture</title>
        <pubDate>Sat, 14 Dec 2013 14:48:21 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
I'm getting several of thee day day:
&lt;/p&gt;
&lt;pre class="wiki"&gt;From: Mail Delivery System &amp;lt;Mailer-Daemon@parrot.webarch.net&amp;gt;
Date: Sat, 14 Dec 2013 13:21:02 +0000
To: tc@parrot.webarch.net
Subject: Mail delivery failed: returning message to sender
This message was created automatically by mail delivery software.
A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:
  inxzkysnf@gmail.com
    SMTP error from remote mail server after RCPT TO:&amp;lt;inxzkysnf@gmail.com&amp;gt;:
    host gmail-smtp-in.l.google.com [173.194.78.26]:
    550-5.1.1 The email account that you tried to reach does not exist. Please try
    550-5.1.1 double-checking the recipient's email address for typos or
    550-5.1.1 unnecessary spaces. Learn more at
    550 5.1.1 http://support.google.com/mail/bin/answer.py?answer=6596 l11si2175565wjw.16 - gsmtp
------ This is a copy of the message, including all the headers. ------
Return-path: &amp;lt;tc@parrot.webarch.net&amp;gt;
Received: from tc (uid=1011)
        by parrot.webarch.net with local (Exim 4.80)
        (envelope-from &amp;lt;tc@parrot.webarch.net&amp;gt;)
        id 1Vrp9L-0002BF-Kf
        for inxzkysnf@gmail.com; Sat, 14 Dec 2013 13:20:56 +0000
To: inxzkysnf@gmail.com
Subject: Thanks for your message
X-PHP-Originating-Script: 1011:lib_nonajax.php
From: robjhopkins@gmail.com
Reply-To: robjhopkins@gmail.com
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----MIME_BOUNDRY_main_message"
Message-Id: &amp;lt;E1Vrp9L-0002BF-Kf@parrot.webarch.net&amp;gt;
Date: Sat, 14 Dec 2013 13:20:55 +0000
This is a multi-part message in MIME format.
------MIME_BOUNDRY_main_message
Content-Type: text/plain; charset="UTF-8"; format=flowed
Content-Transfer-Encoding: quoted-printable
Dear timberland france,
Thank you for your message on the Transition Culture website - I will get back to you as soon as possible.
------MIME_BOUNDRY_main_message
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
&amp;lt;!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"&amp;gt;
&amp;lt;HTML&amp;gt;&amp;lt;BODY&amp;gt;
&amp;lt;div style=3D"font:normal 1em arial; margin-top:10px"&amp;gt;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Dear timberland france,&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Thank you for your message on the Transition Culture website - I will get back to you as soon as possible.
&amp;lt;div style=3D"width:80%; background:#f4faff ; color:#aaa; font-size:11px; padding:10px; margin-top:20px"&amp;gt;&amp;lt;strong&amp;gt;This is an automatic
+confirmation message. 14 December, 2013.&amp;lt;/strong&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;/BODY&amp;gt;&amp;lt;/HTML&amp;gt;
&lt;/pre&gt;&lt;p&gt;
It appears to be spam sent fro the Transition Culture &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; site to a Gnmail user who doesn't exist.
&lt;/p&gt;
&lt;p&gt;
It appears, from the email headers that this form is being used for the spamming &lt;tt&gt;/home/tc/sites/default/wp-content/plugins/contactforms/lib_nonajax.php&lt;/tt&gt;.
&lt;/p&gt;
&lt;p&gt;
This needs some more investigation.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/656#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/687</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/687</guid>
        <title>#687: Set up cert expiry date checking for all SSL certs</title>
        <pubDate>Mon, 03 Feb 2014 13:35:01 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Last month the &lt;tt&gt;*.transitionnetwork.org&lt;/tt&gt; cert expired before it was replaced with a new one and users therefore got warnings for around half a day, see &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/685" title="task: SSL certificate about to expire? (closed: fixed)"&gt;ticket:685&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
A script to check the expiry dates was set up on &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;wiki:PuffinServer&lt;/a&gt; on &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/685#comment:9" title="task: SSL certificate about to expire? (closed: fixed)"&gt;ticket:685#comment:9&lt;/a&gt; and this ticket is to document setting this up for &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PenguinServer"&gt;wiki:PenguinServer&lt;/a&gt; and &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;wiki:ParrotServer&lt;/a&gt;.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/687#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/709</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/709</guid>
        <title>#709: Reconomy sites appears to be sending out spam</title>
        <pubDate>Fri, 28 Mar 2014 18:48:53 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
This failed email has just been returned:
&lt;/p&gt;
&lt;pre class="wiki"&gt;From: Mail Delivery System &amp;lt;Mailer-Daemon@parrot.webarch.net&amp;gt;
Date: Fri, 28 Mar 2014 18:14:32 +0000
To: recon@parrot.webarch.net
Subject: Mail delivery failed: returning message to sender
This message was created automatically by mail delivery software.
A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:
  fionaward@transitionnetwork.org
    SMTP error from remote mail server after end of data:
    host mx1.spamfiltering.com [72.249.150.158]: 550 An address in this message (at sleepingteensex . com) is listed on
+sbl-multi.rbl.spamrl.com. Please organise removal and retry.
------ This is a copy of the message, including all the headers. ------
Return-path: &amp;lt;recon@parrot.webarch.net&amp;gt;
Received: from recon (uid=1006)
        by parrot.webarch.net with local (Exim 4.80)
        (envelope-from &amp;lt;recon@parrot.webarch.net&amp;gt;)
        id 1WTbIM-0001Sz-6R
        for fionaward@transitionnetwork.org; Fri, 28 Mar 2014 18:14:22 +0000
To: fionaward@transitionnetwork.org
Subject: roulette89
X-PHP-Originating-Script: 1006:class-phpmailer.php
Date: Fri, 28 Mar 2014 18:14:22 +0000
From: casino10 &amp;lt;fmzsb@www.reconomy.org&amp;gt;
Message-ID: &amp;lt;28cbb75557094e41d2f5e7e070dcd660@www.reconomy.org&amp;gt;
X-Priority: 3
X-Mailer: PHPMailer 5.2.4 (http://code.google.com/a/apache-extras.org/p/phpmailer/)
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset=UTF-8
From: casino10 &amp;lt;fmzsb@www.reconomy.org&amp;gt;
Subject: roulette89
Message Body:
интернет казино игровые автоматы рулетка зарубежный &amp;lt;a href= http://pobedim11.sleepingteensex.com/item280.html &amp;gt;можно ли играть в
+игровые автоматы в интернете на деньги&amp;lt;/a&amp;gt; игровые автоматы через интернет 3g еще &amp;lt;a href= http://pobedim11.sleepingteensex.com &amp;gt;Новый
+Игровой Автомат&amp;lt;/a&amp;gt; казино интернет казань.
--
This mail is sent via contact form on REconomy http://www.reconomyproject.org
&lt;/pre&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/709#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/718</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/718</guid>
        <title>#718: REconomy site showing adverts randomly</title>
        <pubDate>Thu, 10 Apr 2014 08:19:34 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Load &lt;a class="ext-link" href="http://www.reconomy.org"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.reconomy.org&lt;/a&gt; and the first time you get it, and other times at random and you get spam.
&lt;/p&gt;
&lt;p&gt;
URGENT check please - on REconomy and all WP sites...
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/718#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/539</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/539</guid>
        <title>#539: REconomy site migration and updates</title>
        <pubDate>Wed, 01 May 2013 10:01:00 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
This ticket is to keep track of the tasks undertaken and the time spent on the migration of the &lt;a class="ext-link" href="http://www.reconomy.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.reconomy.org/&lt;/a&gt; site to &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;wiki:ParrotServer&lt;/a&gt;.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/539#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/749</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/749</guid>
        <title>#749: Probs with REconomy site again - compromised?</title>
        <pubDate>Thu, 26 Jun 2014 11:18:01 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Email from Laura:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Looks like REconomy website has been compromised again.
&lt;/p&gt;
&lt;p&gt;
Fi contacted this morning via email to say she's received a batch of
'new post' notifications on exceedingly old posts, so I logged into the
site to check things out. I noted the footer wasn't correct on the site
too displaying 'proudly powered by wordpress' rather than the widgets.
&lt;/p&gt;
&lt;p&gt;
Had a whizz through folders/files via sftp to see any recent changes to
files - and in the Reconomy theme files the 404.php and footer.php had
been changed with a copy of the default wp twenty something one and base
code 64 along the top.  The footer was changed on 23/6 at 21.46, and I
should have remembered when the 404 was changed before overwriting it -
either the same date or time or on the 20/6.
I've reinstated the correct files (but have downloaded a copy of the
rogue 404 and footer files before replacing them with the correct ones
if you wanted a copy for any purpose, though want to nuke these asap
from my machine!)
&lt;/p&gt;
&lt;p&gt;
Unlike the last time, no extra 'odd plugins' seem to have been added,
nor anything odd by a (very) quick scan in wp-content/uploads folders
and sub-folders.
&lt;/p&gt;
&lt;p&gt;
Not sure how this has happened again, be good to know if you can spot
anything your side, esp how these attacks happen especially incase I
need to do something with the theme files (eg could it be some form of
injection attack via the comments form somehow? Can't see how, but just
wondering how these things tend to happen!). (do you think the file
perms okay on the theme files, maybe worth a check too?). People can't
register for an account on the website any longer, new users are added
manually (been the case for some while now to stop spam signups)
&lt;/p&gt;
&lt;p&gt;
All wp core is up-to date btw, and I've updated a couple of plugins
whilst in there today.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
And a follow up:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Following on from previous message just now, and quite poss unrelated
altogether to the current site issue, looking at some of their blog
posts on the site such as this one -
&lt;a class="ext-link" href="http://www.reconomy.org/get-your-oats-here/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.reconomy.org/get-your-oats-here/&lt;/a&gt;,  trackbacks come from a
scraper type site eg -
&lt;a class="ext-link" href="http://500biz.com/realwealth/get-your-oats-here-community-support-helps-new-enterprise-transform-local-food-supply-chain/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://500biz.com/realwealth/get-your-oats-here-community-support-helps-new-enterprise-transform-local-food-supply-chain/&lt;/a&gt;
which seems to reprint reconomys posts.
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/749#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/542</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/542</guid>
        <title>#542: Parrot RAM</title>
        <pubDate>Wed, 01 May 2013 20:35:50 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
I'm concerned that &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;wiki:ParrotServer&lt;/a&gt; might not be able to cope with load spikes due to it only having 1GB of RAM, these are the Munin graphs we need to key an eye on:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/parrot.transitionnetwork.org/swap.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;swap&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/parrot.transitionnetwork.org/memory.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;memory usage&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/parrot.transitionnetwork.org/multips_memory.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;apache2 and mysql memory usage&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
If the server runs out of RAM it will basically stop responding.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/542#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/631</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/631</guid>
        <title>#631: Move Transition Culture onto PARROT</title>
        <pubDate>Mon, 25 Nov 2013 11:57:44 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
We are about to move TC onto PARROT. List of likely actions here:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Ed speak to Simon (move the host, keep the developer if poss)
&lt;/li&gt;&lt;li&gt;Chris speak to Simon about TC issues - traffic, size etc.
&lt;/li&gt;&lt;li&gt;analyse TC traffic and DB size
&lt;/li&gt;&lt;li&gt;prepare PARROT
&lt;/li&gt;&lt;li&gt;move TC
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Chris thinks we'll need to up PARROT to
VPS2 + 2 GB RAM
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/631#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/891</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/891</guid>
        <title>#891: Issue with TTT and REconomy websites after upgrade to WP 4.4</title>
        <pubDate>Thu, 17 Dec 2015 11:18:38 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Email from Laura:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Just to let you know there's a bit of an oddity going on with both the TTT and
Reconomy websites.
&lt;/p&gt;
&lt;p&gt;
I upgraded to WP 4.4 after running full tests on my local copies here, and for
some odd reason images aren't showing on the site.  If you try to open an
image in the browser eg
&lt;a class="ext-link" href="https://www.reconomy.org/wp-content/uploads/2015/10/hubs-logos-landscape.jpg"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.reconomy.org/wp-content/uploads/2015/10/hubs-logos-landscape.jpg&lt;/a&gt;
takes you to the -
"Server error!
The server encountered an internal error and was unable to complete your
request
Either the server is overloaded or there was an error in a CGI script.
Please return to the front page of the site."
&lt;/p&gt;
&lt;p&gt;
I've updated over 20 sites over the past few days (!) and these are the only
two this has happened on.
There are a few discussions here, (and have tried the temp fix of various
functions.php tweaks in the theme files to see if that helps, but it
doesn't)...
&lt;a class="ext-link" href="https://wordpress.org/support/topic/after-upgrade-to-44-media-files-are-not-showing"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wordpress.org/support/topic/after-upgrade-to-44-media-files-are-not-showing&lt;/a&gt;
and even though sites are not appearing to use SSL wondering if related
somehow to that or other? Has this happened to any other WP 4.4 sites on your
servers?
&lt;/p&gt;
&lt;p&gt;
I'll let TTT and REconomy know their site has been updated, but there is a
glitch at present.
&lt;/p&gt;
&lt;p&gt;
I've also added Wordfence to the sites too as there are swathes of brute force
attacks happening on lots of WP sites everywhere currently and this plugin
seems to help somewhat currently.  I don't think it's the Wordfence plugin, as
disabled it to test the missing images issue.
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/891#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/710</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/710</guid>
        <title>#710: Incorrect email address for Sam on Transition Culture</title>
        <pubDate>Tue, 01 Apr 2014 12:01:47 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
I'm seeing quite a few emails like this:
&lt;/p&gt;
&lt;pre class="wiki"&gt;From: Mail Delivery System &amp;lt;Mailer-Daemon@parrot.webarch.net&amp;gt;
Date: Tue, 01 Apr 2014 08:04:28 +0100
To: tc@parrot.webarch.net
Subject: Mail delivery failed: returning message to sender
This message was created automatically by mail delivery software.
A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:
  samrossiter@transitionentwork.org
    Unrouteable address
------ This is a copy of the message, including all the headers. ------
Return-path: &amp;lt;tc@parrot.webarch.net&amp;gt;
Received: from tc (uid=1011)
        by parrot.webarch.net with local (Exim 4.80)
        (envelope-from &amp;lt;tc@parrot.webarch.net&amp;gt;)
        id 1WUskG-0005Rv-Sa
        for samrossiter@transitionentwork.org; Tue, 01 Apr 2014 08:04:28 +0100
To: samrossiter@transitionentwork.org
Subject: [Wordfence Alert] Problems found on Transition Culture
X-PHP-Originating-Script: 1011:class-phpmailer.php
Date: Tue, 1 Apr 2014 07:04:28 +0000
From: WordPress &amp;lt;wordpress@transitionculture.org&amp;gt;
Message-ID: &amp;lt;11e64e1b3cdb24f69d0069ecdc224524@transitionculture.org&amp;gt;
X-Priority: 3
X-Mailer: PHPMailer 5.2.4 (http://code.google.com/a/apache-extras.org/p/phpmailer/)
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset=UTF-8
Wordfence found the following new issues on "Transition Culture".
NOTE: Upgrading to the paid version of Wordfence gives you two factor authentication (sign-in via cellphone)
and country blocking which are both effective methods to block attacks.
You can also schedule when your scans occur with Wordfence Premium.
Click here to sign-up for the Premium version of Wordfence now.
https://www.wordfence.com/wordfence-signup/
Alert generated at Tuesday 1st of April 2014 at 08:04:28 AM
Critical Problems:
* The Plugin "Spam Destroyer" needs an upgrade.
&lt;/pre&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/710#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/921</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/921</guid>
        <title>#921: HTTP_PROXY env var vulnerability</title>
        <pubDate>Tue, 19 Jul 2016 12:34:30 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
See &lt;a class="ext-link" href="https://httpoxy.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://httpoxy.org/&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/921#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/695</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/695</guid>
        <title>#695: File upload problem with TTT WordPress site</title>
        <pubDate>Sun, 02 Mar 2014 19:46:50 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Laura has reported:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Had a report this evening that the TTT website isn't letting any uploads happen (adding of a new plugin by another admin, and also media/image uploads not being able to uploaded - no real error message as such just doesn't upload).
&lt;/p&gt;
&lt;p&gt;
I just logged in quickly to see if I could upload a pic to test and wouldn't upload.
Just wanted to check if anything had changed server side re permissions.
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/695#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/911</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/911</guid>
        <title>#911: Disk space for /home on Parrot is running out</title>
        <pubDate>Mon, 30 May 2016 20:58:53 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Getting this alert from &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;ParrotServer&lt;/a&gt; every 5 mins:
&lt;/p&gt;
&lt;pre class="wiki"&gt;transitionnetwork.org :: parrot.transitionnetwork.org :: Disk usage in percent
        WARNINGs: /home is 96.06 (outside range [:96]).
        OKs: /run/shm is 0.00, /run is 0.09, /dev is 0.00, / is 95.94, / is 95.94, /run/lock is 0.00.
&lt;/pre&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/911#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/696</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/696</guid>
        <title>#696: Disk space error on parrot for TTT site</title>
        <pubDate>Mon, 03 Mar 2014 10:51:46 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Email from Laura:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Message appearing at top of ttt website when I just took a look-
&lt;/p&gt;
&lt;pre class="wiki"&gt;Warning: session_start():
open(/home/ttt/tmp/sess_mnme76d2k5s6vopk5u1it126p5, O_RDWR) failed: No
space left on device (28) in
/home/ttt/sites/default/wp-content/plugins/tt-resource-database/participants-database.php
on line 2534
&lt;/pre&gt;&lt;p&gt;
and something in the sidebar -
&lt;/p&gt;
&lt;pre class="wiki"&gt;Warning: call_user_func_array() expects parameter 1 to be a valid
callback, array must have exactly two members in
/home/ttt/sites/default/wp-includes/plugin.php on line 199
&lt;/pre&gt;&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/696#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/829</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/829</guid>
        <title>#829: Creation of web space request</title>
        <pubDate>Mon, 02 Feb 2015 10:11:03 GMT</pubDate>
        
        <dc:creator>ade</dc:creator>

        <description>&lt;p&gt;
Hi Chris,
As discussed, can you please set up some webspace on Penguin?
If you could also set up a sub-domain of 'projects' and confirm the FTP access details?
&lt;/p&gt;
&lt;p&gt;
Many thanks
Ade
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/829#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/639</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/639</guid>
        <title>#639: earthin site wordpress error</title>
        <pubDate>Fri, 29 Nov 2013 14:06:01 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
When using wp on the command line for &lt;a class="wiki" href="http://localhost:8080/trac/wiki/EarthInheritorsWordPress"&gt;wiki:EarthInheritorsWordPress&lt;/a&gt;
&lt;/p&gt;
&lt;pre class="wiki"&gt;PHP Fatal error:  Call to undefined function get_post_format_slugs() in /home/earthin/sites/default/wp-includes/theme.php on line 1264
&lt;/pre&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/639#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/914</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/914</guid>
        <title>#914: SSH to parrot please</title>
        <pubDate>Wed, 13 Jul 2016 10:58:05 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi Chris
&lt;/p&gt;
&lt;p&gt;
Could you set up a SSH account on parrot for:
&lt;/p&gt;
&lt;p&gt;
Kevin
support@…
&lt;/p&gt;
&lt;p&gt;
Using this public key
&lt;/p&gt;
&lt;p&gt;
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCgO8Uuk3ry+NvVvScbhV+edjJK8evIwnhoi1in1FtWvFTSjjb0NkZLXN5VEsWzq3TPvECggpAgVtdXFoCbmv6+wLKpLoVR7ZU+qcFOlEhVKju0zFRoIl25O9Hv5YqBPXgwzXKJg/ftiKWllXm6pZ97hAwxPoqBj42jwRlyndNLMozjomvXIxiNzgf95BmY7jVDc/JH2Dixe9poLWknXglTPAVHL5UtiP37dsgJj4JgWH9BqFixlEUopcLHhv6KPZpP5WS476KKV6MeiJhLeBpir8JcmqR84Lsoq2z9PUbZ4HyTUBTlMY4j9npFFF+Wqhrk3wxY6Q8TxdTrQDUC5VZ9GYufRS/ep2GPOg67wyOHoYdW3n7l+bX9+pWktD3KyA0KiJqhKG7BTNuhDYl0JqX396H+p80EAhAtFRj8+CnQRVYzogLGExhrKnlptT88rmqx5uJxSqGuuHrmcgncHH6f+qJzaecirJgFKSyPKtESFtBCAdKjbuh22o1EZTARNpdBWtwKNr3BG7D0RzpgVIoEiAxDw9YRSFHmra8pxd/k7F0ue51JO5RUsMxZ0izrgqHkefE+D6uf151Uj8V9Y+rK8C7Hqnc+bOvwixkkwSfglBIz+Y+3YzhEnCf1yCv2TpFnHGLYu0iDTwubDMBIUogi/m/lmGuR0DYxmpwxFNmNww== root@transition
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/914#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/915</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/915</guid>
        <title>#915: SSH to parrot please</title>
        <pubDate>Wed, 13 Jul 2016 10:58:11 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi Chris
&lt;/p&gt;
&lt;p&gt;
Could you set up a SSH account on parrot for:
&lt;/p&gt;
&lt;p&gt;
Kevin
support@…
&lt;/p&gt;
&lt;p&gt;
Using this public key
&lt;/p&gt;
&lt;p&gt;
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCgO8Uuk3ry+NvVvScbhV+edjJK8evIwnhoi1in1FtWvFTSjjb0NkZLXN5VEsWzq3TPvECggpAgVtdXFoCbmv6+wLKpLoVR7ZU+qcFOlEhVKju0zFRoIl25O9Hv5YqBPXgwzXKJg/ftiKWllXm6pZ97hAwxPoqBj42jwRlyndNLMozjomvXIxiNzgf95BmY7jVDc/JH2Dixe9poLWknXglTPAVHL5UtiP37dsgJj4JgWH9BqFixlEUopcLHhv6KPZpP5WS476KKV6MeiJhLeBpir8JcmqR84Lsoq2z9PUbZ4HyTUBTlMY4j9npFFF+Wqhrk3wxY6Q8TxdTrQDUC5VZ9GYufRS/ep2GPOg67wyOHoYdW3n7l+bX9+pWktD3KyA0KiJqhKG7BTNuhDYl0JqX396H+p80EAhAtFRj8+CnQRVYzogLGExhrKnlptT88rmqx5uJxSqGuuHrmcgncHH6f+qJzaecirJgFKSyPKtESFtBCAdKjbuh22o1EZTARNpdBWtwKNr3BG7D0RzpgVIoEiAxDw9YRSFHmra8pxd/k7F0ue51JO5RUsMxZ0izrgqHkefE+D6uf151Uj8V9Y+rK8C7Hqnc+bOvwixkkwSfglBIz+Y+3YzhEnCf1yCv2TpFnHGLYu0iDTwubDMBIUogi/m/lmGuR0DYxmpwxFNmNww== root@transition
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/915#changelog</comments>
    </item>
 </channel>
</rss>