<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #656: Spam being sent out via Transition Culture</title>
    <link>http://localhost:8080/trac/ticket/656</link>
    <description>&lt;p&gt;
I'm getting several of thee day day:
&lt;/p&gt;
&lt;pre class="wiki"&gt;From: Mail Delivery System &amp;lt;Mailer-Daemon@parrot.webarch.net&amp;gt;
Date: Sat, 14 Dec 2013 13:21:02 +0000
To: tc@parrot.webarch.net
Subject: Mail delivery failed: returning message to sender
This message was created automatically by mail delivery software.
A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:
  inxzkysnf@gmail.com
    SMTP error from remote mail server after RCPT TO:&amp;lt;inxzkysnf@gmail.com&amp;gt;:
    host gmail-smtp-in.l.google.com [173.194.78.26]:
    550-5.1.1 The email account that you tried to reach does not exist. Please try
    550-5.1.1 double-checking the recipient's email address for typos or
    550-5.1.1 unnecessary spaces. Learn more at
    550 5.1.1 http://support.google.com/mail/bin/answer.py?answer=6596 l11si2175565wjw.16 - gsmtp
------ This is a copy of the message, including all the headers. ------
Return-path: &amp;lt;tc@parrot.webarch.net&amp;gt;
Received: from tc (uid=1011)
        by parrot.webarch.net with local (Exim 4.80)
        (envelope-from &amp;lt;tc@parrot.webarch.net&amp;gt;)
        id 1Vrp9L-0002BF-Kf
        for inxzkysnf@gmail.com; Sat, 14 Dec 2013 13:20:56 +0000
To: inxzkysnf@gmail.com
Subject: Thanks for your message
X-PHP-Originating-Script: 1011:lib_nonajax.php
From: robjhopkins@gmail.com
Reply-To: robjhopkins@gmail.com
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----MIME_BOUNDRY_main_message"
Message-Id: &amp;lt;E1Vrp9L-0002BF-Kf@parrot.webarch.net&amp;gt;
Date: Sat, 14 Dec 2013 13:20:55 +0000
This is a multi-part message in MIME format.
------MIME_BOUNDRY_main_message
Content-Type: text/plain; charset="UTF-8"; format=flowed
Content-Transfer-Encoding: quoted-printable
Dear timberland france,
Thank you for your message on the Transition Culture website - I will get back to you as soon as possible.
------MIME_BOUNDRY_main_message
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
&amp;lt;!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"&amp;gt;
&amp;lt;HTML&amp;gt;&amp;lt;BODY&amp;gt;
&amp;lt;div style=3D"font:normal 1em arial; margin-top:10px"&amp;gt;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Dear timberland france,&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Thank you for your message on the Transition Culture website - I will get back to you as soon as possible.
&amp;lt;div style=3D"width:80%; background:#f4faff ; color:#aaa; font-size:11px; padding:10px; margin-top:20px"&amp;gt;&amp;lt;strong&amp;gt;This is an automatic
+confirmation message. 14 December, 2013.&amp;lt;/strong&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;/BODY&amp;gt;&amp;lt;/HTML&amp;gt;
&lt;/pre&gt;&lt;p&gt;
It appears to be spam sent fro the Transition Culture &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; site to a Gnmail user who doesn't exist.
&lt;/p&gt;
&lt;p&gt;
It appears, from the email headers that this form is being used for the spamming &lt;tt&gt;/home/tc/sites/default/wp-content/plugins/contactforms/lib_nonajax.php&lt;/tt&gt;.
&lt;/p&gt;
&lt;p&gt;
This needs some more investigation.
&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/656</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Sat, 14 Dec 2013 14:48:42 GMT</pubDate>
      <title>summary changed</title>
      <link>http://localhost:8080/trac/ticket/656#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/656#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;summary&lt;/strong&gt;
                changed from &lt;em&gt;Spam being sent out vi Transition Culture&lt;/em&gt; to &lt;em&gt;Spam being sent out via Transition Culture&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Mon, 10 Mar 2014 14:29:31 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/656#comment:2</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/656#comment:2</guid>
      <description>
        &lt;p&gt;
Hi Chris
&lt;/p&gt;
&lt;p&gt;
I'd stick &lt;a class="ext-link" href="http://wordpress.org/plugins/wordfence/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://wordpress.org/plugins/wordfence/&lt;/a&gt; on the site &amp;amp; see if it detects any malware.
&lt;/p&gt;
&lt;p&gt;
Shall I do this?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 10 Mar 2014 14:43:39 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/656#comment:3</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/656#comment:3</guid>
      <description>
        &lt;p&gt;
Sure, this is an ongoing issue, I get several bounced spam emails a day from the TC site, I have been leaving things like this on the back-burner in part to save the Transition Network money and in part because I'm not a &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; expert, I'm happy for you to take a lead on &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; issues.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Mon, 10 Mar 2014 15:48:17 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/656#comment:4</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/656#comment:4</guid>
      <description>
        &lt;p&gt;
Hi Chris.
&lt;/p&gt;
&lt;p&gt;
Not sure i'm a Wordpress expert either. I have been using it for a few years on various projects. I'm happy to take this on.
&lt;/p&gt;
&lt;p&gt;
Let's continue the conversation here: &lt;a class="ext-link" href="https://trac.transitionnetwork.org/trac/ticket/699"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://trac.transitionnetwork.org/trac/ticket/699&lt;/a&gt; where i'll document what I do.
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Mon, 10 Mar 2014 16:16:29 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/656#comment:5</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/656#comment:5</guid>
      <description>
        &lt;p&gt;
Wrong thread.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Wed, 02 Apr 2014 10:36:13 GMT</pubDate>
      <title>status changed; resolution set</title>
      <link>http://localhost:8080/trac/ticket/656#comment:6</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/656#comment:6</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
This appears to be now resolved.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>