<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #709: Reconomy sites appears to be sending out spam</title>
    <link>http://localhost:8080/trac/ticket/709</link>
    <description>&lt;p&gt;
This failed email has just been returned:
&lt;/p&gt;
&lt;pre class="wiki"&gt;From: Mail Delivery System &amp;lt;Mailer-Daemon@parrot.webarch.net&amp;gt;
Date: Fri, 28 Mar 2014 18:14:32 +0000
To: recon@parrot.webarch.net
Subject: Mail delivery failed: returning message to sender
This message was created automatically by mail delivery software.
A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:
  fionaward@transitionnetwork.org
    SMTP error from remote mail server after end of data:
    host mx1.spamfiltering.com [72.249.150.158]: 550 An address in this message (at sleepingteensex . com) is listed on
+sbl-multi.rbl.spamrl.com. Please organise removal and retry.
------ This is a copy of the message, including all the headers. ------
Return-path: &amp;lt;recon@parrot.webarch.net&amp;gt;
Received: from recon (uid=1006)
        by parrot.webarch.net with local (Exim 4.80)
        (envelope-from &amp;lt;recon@parrot.webarch.net&amp;gt;)
        id 1WTbIM-0001Sz-6R
        for fionaward@transitionnetwork.org; Fri, 28 Mar 2014 18:14:22 +0000
To: fionaward@transitionnetwork.org
Subject: roulette89
X-PHP-Originating-Script: 1006:class-phpmailer.php
Date: Fri, 28 Mar 2014 18:14:22 +0000
From: casino10 &amp;lt;fmzsb@www.reconomy.org&amp;gt;
Message-ID: &amp;lt;28cbb75557094e41d2f5e7e070dcd660@www.reconomy.org&amp;gt;
X-Priority: 3
X-Mailer: PHPMailer 5.2.4 (http://code.google.com/a/apache-extras.org/p/phpmailer/)
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset=UTF-8
From: casino10 &amp;lt;fmzsb@www.reconomy.org&amp;gt;
Subject: roulette89
Message Body:
интернет казино игровые автоматы рулетка зарубежный &amp;lt;a href= http://pobedim11.sleepingteensex.com/item280.html &amp;gt;можно ли играть в
+игровые автоматы в интернете на деньги&amp;lt;/a&amp;gt; игровые автоматы через интернет 3g еще &amp;lt;a href= http://pobedim11.sleepingteensex.com &amp;gt;Новый
+Игровой Автомат&amp;lt;/a&amp;gt; казино интернет казань.
--
This mail is sent via contact form on REconomy http://www.reconomyproject.org
&lt;/pre&gt;</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/709</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 28 Mar 2014 18:58:34 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/709#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/709#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.15&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.15&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
The Transition Culture site also appears to be sending out spam, see &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/656" title="maintenance: Spam being sent out via Transition Culture (closed: fixed)"&gt;ticket:656&lt;/a&gt;, Sam installed wordfence to block it there.
&lt;/p&gt;
&lt;p&gt;
I have glanced through the logs and haven't found the POST/GET's related to this spam, my guess would be that the site has been compromised, but more time is needed to track the cause of this down.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Sat, 29 Mar 2014 20:17:13 GMT</pubDate>
      <title>cc changed</title>
      <link>http://localhost:8080/trac/ticket/709#comment:2</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/709#comment:2</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;cc&lt;/strong&gt;
              &lt;em&gt;sam&lt;/em&gt; added
            &lt;/li&gt;
          &lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>laura</dc:creator>

      <pubDate>Sun, 30 Mar 2014 10:15:09 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/709#comment:3</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/709#comment:3</guid>
      <description>
        &lt;pre class="wiki"&gt;Not sure if this is the same issue that Fi contacted me about this
weekend, (contact form spam - Fi receiving some odd messages in russian)
- so as a temp fix until back at the desk next week, have added some
askimet checks to the name/email field for the contact form (It's really
basic and may not make any difference) and the simple quiz.
There is a more secure contact form plugin which I may set up and config
this week which works well to thwart spammers (eg - works better with
askimet as contact form 7 isn't that great when spammers start using the
form, it also has a hidden but accessible for screenreaders field for
trapping bots and other elements too
https://wordpress.org/plugins/si-contact-form/), and if needed can add
Perishable Press's 5G blacklist to htaccess too.
Laura
On 29/03/2014 20:17, Transiton Technology Trac wrote:
&amp;gt; #709: Reconomy sites appears to be sending out spam
&amp;gt; -------------------------------------+-------------------------------------
&amp;gt;             Reporter:  chris          |                      Owner:  chris
&amp;gt;                 Type:  maintenance    |                     Status:  new
&amp;gt;             Priority:  critical       |                  Milestone:
&amp;gt;            Component:  Parrot server  |  Maintenance
&amp;gt;             Keywords:                 |                 Resolution:
&amp;gt; Add Hours to Ticket:  0              |  Estimated Number of Hours:  0.0
&amp;gt;          Total Hours:  0.15           |                  Billable?:  1
&amp;gt; -------------------------------------+-------------------------------------
&amp;gt; Changes (by ed):
&amp;gt;
&amp;gt;   * cc: sam (added)
&amp;gt;
&amp;gt;
&lt;/pre&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 31 Mar 2014 09:57:34 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/709#comment:4</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/709#comment:4</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.15&lt;/em&gt; to &lt;em&gt;0.4&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/709#comment:3" title="Comment 3 for Ticket #709"&gt;laura&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Not sure if this is the same issue that Fi contacted me about this
weekend, (contact form spam - Fi receiving some odd messages in russian)
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Yes I expect it will be, the messages she will have got will be the ones that got through the filters at the transitionnetwork.org mailserver - mx1.spamfiltering.com.
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;ul&gt;&lt;li&gt;so as a temp fix until back at the desk next week, have added some
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
askimet checks to the name/email field for the contact form (It's really
basic and may not make any difference) and the simple quiz.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
I got three returned emails yesterday, see the end of this message.
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
There is a more secure contact form plugin which I may set up and config
this week which works well to thwart spammers (eg - works better with
askimet as contact form 7 isn't that great when spammers start using the
form, it also has a hidden but accessible for screenreaders field for
trapping bots and other elements too
&lt;a class="ext-link" href="https://wordpress.org/plugins/si-contact-form/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wordpress.org/plugins/si-contact-form/&lt;/a&gt;), and if needed can add
Perishable Press's 5G blacklist to htaccess too.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Thanks, looking at the emails below it does look like a spam bot has signed up for an account and then used the contact form to send a email to fionaward@… and then the transitionnetwork.org mailserver at mx1.spamfiltering.com has bounced it back to the web servers root email address as the messages contain &lt;em&gt;"An address in this message (at sleepingteensex . com) is listed on sbl-multi.rbl.spamrl.com"&lt;/em&gt;.
&lt;/p&gt;
&lt;p&gt;
These are the three returned emails from yesterday:
&lt;/p&gt;
&lt;pre class="wiki"&gt;From: Mail Delivery System &amp;lt;Mailer-Daemon@parrot.webarch.net&amp;gt;
Date: Sun, 30 Mar 2014 00:51:49 +0000
To: recon@parrot.webarch.net
Subject: Mail delivery failed: returning message to sender
This message was created automatically by mail delivery software.
A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:
  fionaward@transitionnetwork.org
    SMTP error from remote mail server after end of data:
    host mx1.spamfiltering.com [212.113.130.124]:
    550 An address in this message (at sleepingteensex . com) is listed on sbl-multi.rbl.spamrl.com. Please organise removal and retry.
------ This is a copy of the message, including all the headers. ------
Return-path: &amp;lt;recon@parrot.webarch.net&amp;gt;
Received: from recon (uid=1006)
        by parrot.webarch.net with local (Exim 4.80)
        (envelope-from &amp;lt;recon@parrot.webarch.net&amp;gt;)
        id 1WU3yO-0003lS-52
        for fionaward@transitionnetwork.org; Sun, 30 Mar 2014 00:51:40 +0000
To: fionaward@transitionnetwork.org
Subject: slots27
X-PHP-Originating-Script: 1006:class-phpmailer.php
Date: Sun, 30 Mar 2014 00:51:40 +0000
From: roulette40 &amp;lt;mtollui@www.reconomy.org&amp;gt;
Message-ID: &amp;lt;c2f84bd0a251e665b87ed4dade5f3ded@www.reconomy.org&amp;gt;
X-Priority: 3
X-Mailer: PHPMailer 5.2.4 (http://code.google.com/a/apache-extras.org/p/phpmailer/)
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset=UTF-8
From: roulette40 &amp;lt;mtollui@www.reconomy.org&amp;gt;
Subject: slots27
Message Body:
интернет казино gambling, игровые автоматы бесплатно регистрации &amp;lt;a href= http://pobedim15.sleepingteensex.com/item1393.html &amp;gt;играть в
+игровые автоматы вулкан онлайн на деньги&amp;lt;/a&amp;gt; игровые автоматы играть бесплатно www &amp;lt;a href= http://pobedim15.sleepingteensex.com
+&amp;gt;Лягушки Игровые Автоматы&amp;lt;/a&amp;gt;
--
This mail is sent via contact form on REconomy http://www.reconomyproject.org
&lt;/pre&gt;&lt;pre class="wiki"&gt;From: Mail Delivery System &amp;lt;Mailer-Daemon@parrot.webarch.net&amp;gt;
Date: Sun, 30 Mar 2014 09:03:29 +0100
To: recon@parrot.webarch.net
Subject: Mail delivery failed: returning message to sender
This message was created automatically by mail delivery software.
A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:
  fionaward@transitionnetwork.org
    SMTP error from remote mail server after end of data:
    host mx1.spamfiltering.com [72.249.150.158]: 550 An address in this message (at sleepingteensex . com) is listed on
+sbl-multi.rbl.spamrl.com. Please organise removal and retry.
------ This is a copy of the message, including all the headers. ------
Return-path: &amp;lt;recon@parrot.webarch.net&amp;gt;
Received: from recon (uid=1006)
        by parrot.webarch.net with local (Exim 4.80)
        (envelope-from &amp;lt;recon@parrot.webarch.net&amp;gt;)
        id 1WUAiD-0004qV-3r
        for fionaward@transitionnetwork.org; Sun, 30 Mar 2014 09:03:25 +0100
To: fionaward@transitionnetwork.org
Subject: poker3
X-PHP-Originating-Script: 1006:class-phpmailer.php
Date: Sun, 30 Mar 2014 08:03:25 +0000
From: slot7 &amp;lt;lxabaf@www.reconomy.org&amp;gt;
Message-ID: &amp;lt;bd0b74beb416f4aec759cfbde93516d1@www.reconomy.org&amp;gt;
X-Priority: 3
X-Mailer: PHPMailer 5.2.4 (http://code.google.com/a/apache-extras.org/p/phpmailer/)
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset=UTF-8
From: slot7 &amp;lt;lxabaf@www.reconomy.org&amp;gt;
Subject: poker3
Message Body:
игровой автомат одноглазый джо &amp;lt;a href= http://pobedim16.sleepingteensex.com/entry1056.html &amp;gt;игровые автоматы на деньги для андроид&amp;lt;/a&amp;gt;
+азартные игры игровые автоматы играть бесплатно онлайн &amp;lt;a href= http://pobedim16.sleepingteensex.com/entry1352.html &amp;gt;игры онлайн нарды
+длинные на деньги&amp;lt;/a&amp;gt;
--
This mail is sent via contact form on REconomy http://www.reconomyproject.org
&lt;/pre&gt;&lt;pre class="wiki"&gt;From: Mail Delivery System &amp;lt;Mailer-Daemon@parrot.webarch.net&amp;gt;
Date: Sun, 30 Mar 2014 09:27:34 +0100
To: recon@parrot.webarch.net
Subject: Mail delivery failed: returning message to sender
This message was created automatically by mail delivery software.
A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:
  fionaward@transitionnetwork.org
    SMTP error from remote mail server after end of data:
    host mx1.spamfiltering.com [212.113.130.124]:
    550 An address in this message (at sleepingteensex . com) is listed on sbl-multi.rbl.spamrl.com. Please organise removal and retry.
------ This is a copy of the message, including all the headers. ------
Return-path: &amp;lt;recon@parrot.webarch.net&amp;gt;
Received: from recon (uid=1006)
        by parrot.webarch.net with local (Exim 4.80)
        (envelope-from &amp;lt;recon@parrot.webarch.net&amp;gt;)
        id 1WUB5X-0005v2-Te
        for fionaward@transitionnetwork.org; Sun, 30 Mar 2014 09:27:31 +0100
To: fionaward@transitionnetwork.org
Subject: roulette97
X-PHP-Originating-Script: 1006:class-phpmailer.php
Date: Sun, 30 Mar 2014 08:27:31 +0000
From: slot26 &amp;lt;jahpll@www.reconomy.org&amp;gt;
Message-ID: &amp;lt;ef6b87b1857fa47f7019f3155811835a@www.reconomy.org&amp;gt;
X-Priority: 3
X-Mailer: PHPMailer 5.2.4 (http://code.google.com/a/apache-extras.org/p/phpmailer/)
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset=UTF-8
From: slot26 &amp;lt;jahpll@www.reconomy.org&amp;gt;
Subject: roulette97
Message Body:
казино мелонати или онлайн казино с бездепозитным бонусом &amp;lt;a href= http://baraban12.sleepingteensex.com/info890.html &amp;gt;играть покер
+онлайн на реальные деньги отзывы форум&amp;lt;/a&amp;gt; казино goldsmir &amp;lt;a href= http://baraban12.sleepingteensex.com &amp;gt;Слоты играть на деньги
+рубли&amp;lt;/a&amp;gt;
--
This mail is sent via contact form on REconomy http://www.reconomyproject.org
&lt;/pre&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Tue, 01 Apr 2014 11:58:30 GMT</pubDate>
      <title>hours, priority, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/709#comment:5</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/709#comment:5</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;priority&lt;/strong&gt;
                changed from &lt;em&gt;critical&lt;/em&gt; to &lt;em&gt;minor&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.4&lt;/em&gt; to &lt;em&gt;0.5&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
No new bounces, downgrading Priority to minor.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 02 Jun 2014 09:18:17 GMT</pubDate>
      <title>status changed; resolution set</title>
      <link>http://localhost:8080/trac/ticket/709#comment:6</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/709#comment:6</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
This is no longer an issue.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>