<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #774: * Advisory ID: DRUPAL-SA-CORE-2014-004</title>
    <link>http://localhost:8080/trac/ticket/774</link>
    <description>&lt;p&gt;
View online: &lt;a class="ext-link" href="https://www.drupal.org/SA-CORE-2014-004"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/SA-CORE-2014-004&lt;/a&gt;
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Advisory ID: DRUPAL-SA-CORE-2014-004
&lt;/li&gt;&lt;li&gt;Project: Drupal core &lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Version: 6.x, 7.x
&lt;/li&gt;&lt;li&gt;Date: 2014-August-06
&lt;/li&gt;&lt;li&gt;Security risk: 13/25 ( Moderately Critical)
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
AC:None/A:None/CI:None/II:None/E:Proof/TD:100 &lt;a class="missing changeset" title="No default repository defined"&gt;[2]&lt;/a&gt;
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Exploitable from: Remote
&lt;/li&gt;&lt;li&gt;Vulnerability: Denial of service
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
Drupal 6 and Drupal 7 include an XML-RPC endpoint which is publicly available
(xmlrpc.php). The PHP XML parser used by this XML-RPC endpoint is vulnerable
to an XML entity expansion attack and other related XML payload attacks which
can cause CPU and memory exhaustion and the site's database to reach the
maximum number of open connections. Any of these may lead to the site
becoming unavailable or unresponsive (denial of service).
&lt;/p&gt;
&lt;p&gt;
All Drupal sites are vulnerable to this attack whether XML-RPC is used or
not.
&lt;/p&gt;
&lt;p&gt;
In addition, a similar vulnerability exists in the core OpenID module (for
sites that have this module enabled).
&lt;/p&gt;
&lt;p&gt;
This is a joint release as the XML-RPC vulnerability also affects &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt;
(see the announcement &lt;a class="missing changeset" title="No default repository defined"&gt;[3]&lt;/a&gt;).
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;/A CVE identifier &lt;a class="missing changeset" title="No default repository defined"&gt;[4]&lt;/a&gt; will be requested, and added upon issuance, in
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
accordance
with Drupal Security Team processes./
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Drupal core 7.x versions prior to 7.31.
&lt;/li&gt;&lt;li&gt;Drupal core 6.x versions prior to 6.33.
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
Install the latest version:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;If you use Drupal 7.x, upgrade to Drupal core 7.31 &lt;a class="missing changeset" title="No default repository defined"&gt;[5]&lt;/a&gt;.
&lt;/li&gt;&lt;li&gt;If you use Drupal 6.x, upgrade to Drupal core 6.33 &lt;a class="missing changeset" title="No default repository defined"&gt;[6]&lt;/a&gt;.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
If you are unable to install the latest version of Drupal immediately, you
can alternatively remove the xmlrpc.php file from the root of Drupal core (or
add a rule to .htaccess to prevent access to xmlrpc.php) and disable the
OpenID module. These steps are sufficient to mitigate the vulnerability in
Drupal core if your site does not require the use of XML-RPC or OpenID
functionality. However, this mitigation will not be effective if you are
using a contributed module that exposes Drupal's XML-RPC API at a different
URL (for example, the Services module); updating Drupal core is therefore
strongly recommended.
&lt;/p&gt;
&lt;p&gt;
Also see the Drupal core &lt;a class="missing changeset" title="No default repository defined"&gt;[7]&lt;/a&gt; project page.
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Willis Vandevanter &lt;a class="missing changeset" title="No default repository defined"&gt;[8]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Nir Goldshlager &lt;a class="missing changeset" title="No default repository defined"&gt;[9]&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Andrew Nacin &lt;a class="missing changeset" title="No default repository defined"&gt;[10]&lt;/a&gt; of the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; Security Team
&lt;/li&gt;&lt;li&gt;Michael Adams &lt;a class="missing changeset" title="No default repository defined"&gt;[11]&lt;/a&gt; of the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; Security Team
&lt;/li&gt;&lt;li&gt;Frédéric Marand &lt;a class="missing changeset" title="No default repository defined"&gt;[12]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;David Rothstein &lt;a class="missing changeset" title="No default repository defined"&gt;[13]&lt;/a&gt; of the Drupal Security Team
&lt;/li&gt;&lt;li&gt;Damien Tournoud &lt;a class="missing changeset" title="No default repository defined"&gt;[14]&lt;/a&gt; of the Drupal Security Team
&lt;/li&gt;&lt;li&gt;Greg Knaddison &lt;a class="missing changeset" title="No default repository defined"&gt;[15]&lt;/a&gt; of the Drupal Security Team
&lt;/li&gt;&lt;li&gt;Stéphane Corlosquet &lt;a class="missing changeset" title="No default repository defined"&gt;[16]&lt;/a&gt; of the Drupal Security Team
&lt;/li&gt;&lt;li&gt;Dave Reid &lt;a class="missing changeset" title="No default repository defined"&gt;[17]&lt;/a&gt; of the Drupal Security Team
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;The Drupal Security Team &lt;a class="missing changeset" title="No default repository defined"&gt;[18]&lt;/a&gt; and the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[19]&lt;/a&gt; Security Team
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
The Drupal security team can be reached at security at drupal.org or via the
contact form at &lt;a class="ext-link" href="http://drupal.org/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/contact&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[20]&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
Learn more about the Drupal Security team and their policies &lt;a class="missing changeset" title="No default repository defined"&gt;[21]&lt;/a&gt;, writing
secure code for Drupal &lt;a class="missing changeset" title="No default repository defined"&gt;[22]&lt;/a&gt;, and securing your site &lt;a class="missing changeset" title="No default repository defined"&gt;[23]&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/project/drupal"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/project/drupal&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[2]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security-team/risk-levels"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security-team/risk-levels&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[3]&lt;/a&gt; &lt;a class="ext-link" href="https://wordpress.org/news/2014/08/wordpress-3-9-2/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wordpress.org/news/2014/08/wordpress-3-9-2/&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[4]&lt;/a&gt; &lt;a class="ext-link" href="http://cve.mitre.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://cve.mitre.org/&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[5]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/drupal-7.31-release-notes"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/drupal-7.31-release-notes&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[6]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/drupal-6.33-release-notes"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/drupal-6.33-release-notes&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[7]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/project/drupal"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/project/drupal&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[8]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/1867894"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/1867894&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[9]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/2891345"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/2891345&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[10]&lt;/a&gt; &lt;a class="ext-link" href="http://profiles.wordpress.org/nacin"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://profiles.wordpress.org/nacin&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[11]&lt;/a&gt; &lt;a class="ext-link" href="http://profiles.wordpress.org/mdawaffe"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://profiles.wordpress.org/mdawaffe&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[12]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/27985"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/27985&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[13]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/124982"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/124982&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[14]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/22211"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/22211&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[15]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/u/greggles"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/u/greggles&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[16]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/52142"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/52142&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[17]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/53892"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/53892&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[18]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security-team"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security-team&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[19]&lt;/a&gt; &lt;a class="ext-link" href="http://wordpress.org"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://wordpress.org&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[20]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/contact&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[21]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security-team"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security-team&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[22]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/writing-secure-code"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/writing-secure-code&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[23]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security/secure-configuration"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security/secure-configuration&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;_
Security-news mailing list
Security-news@…
Unsubscribe at &lt;a class="ext-link" href="https://lists.drupal.org/mailman/listinfo/security-news"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://lists.drupal.org/mailman/listinfo/security-news&lt;/a&gt;
&lt;/span&gt;&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/774</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Wed, 06 Aug 2014 19:56:22 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.125&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.125&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
@Annesley
&lt;/p&gt;
&lt;p&gt;
Let me know if you need any help.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 07 Aug 2014 09:01:35 GMT</pubDate>
      <title>owner, priority, component changed; cc, milestone set</title>
      <link>http://localhost:8080/trac/ticket/774#comment:2</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:2</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;cc&lt;/strong&gt;
              &lt;em&gt;chris&lt;/em&gt; added
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;owner&lt;/strong&gt;
              changed from &lt;em&gt;ed&lt;/em&gt; to &lt;em&gt;annesley&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;priority&lt;/strong&gt;
                changed from &lt;em&gt;major&lt;/em&gt; to &lt;em&gt;critical&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;component&lt;/strong&gt;
                changed from &lt;em&gt;Unassigned&lt;/em&gt; to &lt;em&gt;Drupal modules &amp; settings&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;milestone&lt;/strong&gt;
                set to &lt;em&gt;Maintenance&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Annesley this looks like it really needs to be done today, or if you are going to postpone updating Drupal core then you need to add Nginx config to deny access to xmlrpc.php. If you need help with the Nginx config let me know. This also affects &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt;, I'm going to look at the sites on &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;ParrotServer&lt;/a&gt; now.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 07 Aug 2014 09:14:44 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:3</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:3</guid>
      <description>
        &lt;p&gt;
Note that this issue affects all the Drupal sites on &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;wiki:PuffinServer&lt;/a&gt; -- it appear to me that any development sites which are not password protected should also updated.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>annesley</dc:creator>

      <pubDate>Thu, 07 Aug 2014 09:38:15 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:4</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:4</guid>
      <description>
        &lt;p&gt;
does anyone know what is the likelihood of TN.org being the victim of a DDOS or DOS attack?
&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
because DDOS and DOS are not automated, they are individual hackers using it to gain access to banks etc. we are not a target. is this correct? so i put it at 0.00000000001% chance of it happening over the next 5 years.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
how long would it take us (downtime) to solve it in the case of a DOS? 5 hours?
do our IP chains / firewall protect against this? (i think not in this case anyway)
&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;
if it did we could ignore all further DOS Drupal holes. worth installing IP chains burst protection? (excuse my lack of precise knowledge here but you get what i am saying)
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
we seem to have OpenID Module there, but not installed.
we are using Services_Links but not Services.
&lt;/p&gt;
&lt;p&gt;
@chris: do we have a dedicated server or virtual? is there risk to the other sites that you host or from?
&lt;/p&gt;
&lt;p&gt;
i am not against deleting the XMLRPC.php file however. i think we are not providing any XML based services anyway...? have i understood it's role correctly?
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Thu, 07 Aug 2014 09:42:03 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:5</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:5</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.125&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.125&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
@Annesley
&lt;/p&gt;
&lt;p&gt;
We're not using Services or Open ID contrib modules.
On the stage servers I think we can just remove the xmlrpc.php files.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>annesley</dc:creator>

      <pubDate>Thu, 07 Aug 2014 09:47:14 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:6</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:6</guid>
      <description>
        &lt;p&gt;
hmm... mind you, this sort of attack could certainly be very easily automated. even if it hasn't been. a script kiddy could achieve this XML entity expansion attack because it is so simply to do. it doesn't require multi-threaded requests or normal DOS procedures, it's just a recursive entity definition in the DTD of the XML RPC request.
&lt;/p&gt;
&lt;p&gt;
we should delete XMLRPC.php today then. we have no need to expose Remote Procedure Calls anyway AFAIK. and no intention to do this.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>annesley</dc:creator>

      <pubDate>Thu, 07 Aug 2014 09:48:13 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:7</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:7</guid>
      <description>
        &lt;p&gt;
@chris: could you handle the deletion of this file? is that within your role?
&lt;/p&gt;
&lt;p&gt;
thanks :)
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>annesley</dc:creator>

      <pubDate>Thu, 07 Aug 2014 09:49:12 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:8</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:8</guid>
      <description>
        &lt;p&gt;
@Paul: we do have OpenID Module on the server though...
it's showing as "not installed" from drush
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>annesley</dc:creator>

      <pubDate>Thu, 07 Aug 2014 09:53:07 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:9</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:9</guid>
      <description>
        &lt;p&gt;
ok, it seems that removing XMLRPC.php removes the OpenID core module vulnerability as well. according to my understanding...
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Thu, 07 Aug 2014 09:55:35 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:10</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:10</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.125&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.25&lt;/em&gt; to &lt;em&gt;0.375&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
The security team advice that the module just needs to be disabled on the server:
&lt;/p&gt;
&lt;p&gt;
If you are unable to install the latest version of Drupal immediately, you
can alternatively remove the xmlrpc.php file from the root of Drupal core (or
add a rule to .htaccess to prevent access to xmlrpc.php) and disable the
OpenID module.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 07 Aug 2014 09:58:04 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:11</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:11</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.375&lt;/em&gt; to &lt;em&gt;0.625&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
The &lt;a class="ext-link" href="https://www.drupal.org/SA-CORE-2014-004"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;security advisory&lt;/a&gt; says:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
The PHP XML parser used by this XML-RPC endpoint is vulnerable to an XML entity expansion attack and other related XML payload attacks which can cause CPU and memory exhaustion and the site's database to reach the maximum number of open connections. Any of these may lead to the site becoming unavailable or unresponsive (denial of service).
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Since this also applies to &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; it is bound to result in a lot of attention being devoted to any possible automated exploits so it would be sensible to take steps to mitigate the risk. I don't know what the exact potential is for "XML payload attacks" but it is worth noting that we were at the limit of max MySQL connections with the default BOA config until it was increased 6 weeks ago, see &lt;a class="assigned ticket" href="http://localhost:8080/trac/ticket/587#comment:17" title="maintenance: Puffin MySQL Tuning (assigned)"&gt;ticket:587#comment:17&lt;/a&gt;, currently we have 39 with a max of 50:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/mysql_connections.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/mysql_connections.html&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
There are 54 copies of &lt;tt&gt;xmlrpc.php&lt;/tt&gt; on the server. We can't use &lt;tt&gt;.htaccess&lt;/tt&gt; files because we are not using Apache.
&lt;/p&gt;
&lt;p&gt;
It is a virtual server, see: &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer#Puffin"&gt;wiki:PuffinServer#Puffin&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Thu, 07 Aug 2014 10:01:30 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:12</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:12</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.125&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.625&lt;/em&gt; to &lt;em&gt;0.75&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/774#comment:9" title="Comment 9 for Ticket #774"&gt;annesley&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
ok, it seems that removing XMLRPC.php removes the OpenID core module vulnerability as well. according to my understanding...
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
There are two similar vulnerabilities that exists in XML-RPC and the core OpenID module. They probably have some shared code between them.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Thu, 07 Aug 2014 10:04:58 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:13</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:13</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.125&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.75&lt;/em&gt; to &lt;em&gt;0.875&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
@Annesley @Chris
&lt;/p&gt;
&lt;p&gt;
I think we can just delete all of these xmlrpc.php files?
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 07 Aug 2014 10:09:26 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:14</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:14</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.05&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.875&lt;/em&gt; to &lt;em&gt;0.925&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/774#comment:13" title="Comment 13 for Ticket #774"&gt;paul&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I think we can just delete all of these xmlrpc.php files?
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
I can do that if you think it is safe to do so, note that some &lt;tt&gt;xmlrpc.php&lt;/tt&gt; files will get recreated by things like the next BOA update, &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/775" title="maintenance: New BOA-2.2.9 Stable Edition available (closed: fixed)"&gt;ticket:775&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 07 Aug 2014 10:11:07 GMT</pubDate>
      <title>cc changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:15</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:15</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;cc&lt;/strong&gt;
              &lt;em&gt;ed&lt;/em&gt; added
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Added Ed as a Cc.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Thu, 07 Aug 2014 10:14:20 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:16</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:16</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.125&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.925&lt;/em&gt; to &lt;em&gt;1.05&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Good. Thanks Chris.
&lt;/p&gt;
&lt;p&gt;
@Annesley
&lt;/p&gt;
&lt;p&gt;
Maybe delete the xmlrpc.php file now and then follow up with building a new platform for production?
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Thu, 07 Aug 2014 10:15:02 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:17</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:17</guid>
      <description>
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/774#comment:16" title="Comment 16 for Ticket #774"&gt;paul&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Good. Thanks Chris.
&lt;/p&gt;
&lt;p&gt;
@Annesley
&lt;/p&gt;
&lt;p&gt;
Maybe delete the xmlrpc.php files now (with help from Chris) and then follow up with building a new platform for production?
&lt;/p&gt;
&lt;/blockquote&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>annesley</dc:creator>

      <pubDate>Thu, 07 Aug 2014 10:19:23 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:18</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:18</guid>
      <description>
        &lt;p&gt;
let me run a few checks before we delete it.
&lt;/p&gt;
&lt;p&gt;
i will delete it on staging first and have a browse of course. but also check for references in the codebase.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>annesley</dc:creator>

      <pubDate>Thu, 07 Aug 2014 10:26:15 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:19</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:19</guid>
      <description>
        &lt;p&gt;
grep -rsi xmlrpc.php *
includes/common.inc: *     &lt;a class="ext-link" href="http://www.example.com/xmlrpc.php"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.example.com/xmlrpc.php&lt;/a&gt;
modules/blogapi/blogapi.module:  $xmlrpc = $base_url .'/xmlrpc.php';
sites/all/modules/contrib/robotstxt/robots.txt:Disallow: /xmlrpc.php
&lt;/p&gt;
&lt;p&gt;
blog api is "not installed"
&lt;/p&gt;
&lt;p&gt;
so i'll go ahead and delete it from staging now.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Thu, 07 Aug 2014 10:27:55 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:20</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:20</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.125&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;1.05&lt;/em&gt; to &lt;em&gt;1.175&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Building a new platform with latest version of core and then migrating the live site over will fix the problem for the live site and will probably not take more than 15 minutes. So we can have this problem resolved for stage / production within the half hour I would say?
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>annesley</dc:creator>

      <pubDate>Thu, 07 Aug 2014 10:32:56 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:21</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:21</guid>
      <description>
        &lt;p&gt;
@paul: ok
&lt;/p&gt;
&lt;p&gt;
staging seems fine without it's xmlrpc.php of course. there are no links to it except from blogapi.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Thu, 07 Aug 2014 10:35:36 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:22</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:22</guid>
      <description>
        &lt;p&gt;
Cool. Many drupal sites just delete the xmlrpc.php from the server if it's not being used.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Thu, 07 Aug 2014 17:15:32 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:23</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:23</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;1.175&lt;/em&gt; to &lt;em&gt;1.425&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
@Chris
&lt;/p&gt;
&lt;p&gt;
I think these are the version of xmlrpc.php that are not  automatically generated by Aegir:
&lt;/p&gt;
&lt;p&gt;
puffin:~# find / -name xmlrpc.php
/data/disk/tn/static/transition-network-d6-s011/xmlrpc.php
/data/disk/tn/static/transition-network-d6-p010-booker/xmlrpc.php
/data/disk/tn/static/transition-network-d6-s009/xmlrpc.php
/data/disk/tn/static/transition-network-d6-s008/xmlrpc.php
/data/disk/tn/static/transition-network-d6-s012/xmlrpc.php
/data/disk/tn/static/transition-network-d6-p009/xmlrpc.php
/data/disk/tn/static/transition-network-d6-32-p001-booker/xmlrpc.php
&lt;/p&gt;
&lt;p&gt;
/data/disk/tn/static/iirs-d006/xmlrpc.php
/data/disk/tn/static/iirs-d007/xmlrpc.php
/data/disk/tn/distro/007/drupal-7.30.1-prod/xmlrpc.php
/data/disk/tn/distro/007/openatrium-7.x-2.19-7.30.1/xmlrpc.php
/data/disk/tn/distro/006/drupal-7.28.1-prod/xmlrpc.php
/data/disk/tn/distro/006/openatrium-7.x-2.19-7.28.1/xmlrpc.php
/data/disk/tn/distro/005/drupal-7.27.1-prod/xmlrpc.php
/data/disk/tn/distro/005/openatrium-7.x-2.17-7.27.1/xmlrpc.php
/data/disk/tn/distro/004/openatrium-7.x-2.09-7.24.1/xmlrpc.php
/data/disk/tn/distro/004/drupal-7.24.1-prod/xmlrpc.php
...
&lt;/p&gt;
&lt;p&gt;
Do you have any thoughts on dealing with the second block? I'll deal with the first block now ..
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 07 Aug 2014 17:52:30 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:24</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:24</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;1.425&lt;/em&gt; to &lt;em&gt;1.525&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/774#comment:23" title="Comment 23 for Ticket #774"&gt;paul&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
/data/disk/tn/static/iirs-d006/xmlrpc.php
/data/disk/tn/static/iirs-d007/xmlrpc.php
/data/disk/tn/distro/007/drupal-7.30.1-prod/xmlrpc.php
/data/disk/tn/distro/007/openatrium-7.x-2.19-7.30.1/xmlrpc.php
/data/disk/tn/distro/006/drupal-7.28.1-prod/xmlrpc.php
/data/disk/tn/distro/006/openatrium-7.x-2.19-7.28.1/xmlrpc.php
/data/disk/tn/distro/005/drupal-7.27.1-prod/xmlrpc.php
/data/disk/tn/distro/005/openatrium-7.x-2.17-7.27.1/xmlrpc.php
/data/disk/tn/distro/004/openatrium-7.x-2.09-7.24.1/xmlrpc.php
/data/disk/tn/distro/004/drupal-7.24.1-prod/xmlrpc.php
...
&lt;/p&gt;
&lt;p&gt;
Do you have any thoughts on dealing with the second block?
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
I think the simplest and quickest thing would be to delete them. I don't know if they are available to the public and the Nginx config is really hard to follow so it would take a while to work out which, if any, are and then to add rules to deny access to the files and then any changes would probably be clobbered at some point...
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Thu, 07 Aug 2014 17:56:51 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:25</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:25</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.75&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;1.525&lt;/em&gt; to &lt;em&gt;2.275&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
@Chris
&lt;/p&gt;
&lt;p&gt;
Agreed. I'll do that shortly.
&lt;/p&gt;
&lt;p&gt;
@TN
&lt;/p&gt;
&lt;p&gt;
What I have done so far:
&lt;/p&gt;
&lt;p&gt;
Deleted my earlier stage sites.
Built a new stage platform.
Migrated the latest version of the stage site over to the new platform.
Turned on the database log &amp;amp; checked the site is working.
&lt;/p&gt;
&lt;p&gt;
The new production platform is now scheduled to be built.  As soon as the platform is built I'll migrate the live site over to the new production platform...
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Thu, 07 Aug 2014 18:17:40 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:26</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:26</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;2.275&lt;/em&gt; to &lt;em&gt;2.525&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
The live site is now migrated to the new production platform &amp;amp; seems to be working fine.
&lt;/p&gt;
&lt;p&gt;
The only xmlrpc.php files that have not been updated or deleted are the aegir versions of the files.
&lt;/p&gt;
&lt;p&gt;
puffin:~# find / -name xmlrpc.php
/data/disk/tn/static/transition-network-d6-33-p001-booker/xmlrpc.php
/data/disk/tn/static/transition-network-d6-33-s001-booker/xmlrpc.php
/data/disk/tn/aegir/distro/009/xmlrpc.php
/data/disk/tn/aegir/distro/011/xmlrpc.php
/data/disk/tn/aegir/distro/010/xmlrpc.php
/data/disk/tn/aegir/distro/008/xmlrpc.php
/data/disk/tn/platforms/transitionnetwork.org/xmlrpc.php
/data/all/000/core/pressflow-6.29.1/xmlrpc.php
/data/all/000/core/drupal-7.23.3/xmlrpc.php
/data/all/000/core/drupal-7.27.1/xmlrpc.php
/data/all/000/core/drupal-7.30.1/xmlrpc.php
/data/all/000/core/pressflow-6.32.2/xmlrpc.php
/data/all/000/core/drupal-7.28.1/xmlrpc.php
/data/all/000/core/drupal-7.24.1/xmlrpc.php
/data/all/000/core/pressflow-6.31.1/xmlrpc.php
/data/all/000/core/pressflow-6.31.2/xmlrpc.php
/data/all/000/core/pressflow-6.28.3/xmlrpc.php
/var/aegir/hostmaster-BOA-2.0.4/xmlrpc.php
/var/aegir/host_master/009/xmlrpc.php
/var/aegir/host_master/001/xmlrpc.php
/var/aegir/host_master/007/xmlrpc.php
/var/aegir/host_master/002/xmlrpc.php
/var/aegir/host_master/003/xmlrpc.php
/var/aegir/host_master/011/xmlrpc.php
/var/aegir/host_master/010/xmlrpc.php
/var/aegir/host_master/013/xmlrpc.php
/var/aegir/host_master/012/xmlrpc.php
/var/aegir/host_master/006/xmlrpc.php
/var/aegir/host_master/005/xmlrpc.php
/var/aegir/host_master/004/xmlrpc.php
/var/aegir/host_master/008/xmlrpc.php
/var/aegir/host_master/014/xmlrpc.php
/var/aegir/host_master/015/xmlrpc.php
/var/backups/trash/drupal-7.22.1/xmlrpc.php
/var/backups/codebases-cleanup/001/pressflow-6.26.2-dev/xmlrpc.php
/var/backups/codebases-cleanup/001/pressflow-6.26.2-stage/xmlrpc.php
/var/backups/codebases-cleanup/001/pressflow-6.26.2-prod/xmlrpc.php
/var/backups/codebases-cleanup/002/drupal-7.22.1-prod/xmlrpc.php
puffin:~#
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 07 Aug 2014 22:24:19 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:27</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:27</guid>
      <description>
        &lt;p&gt;
I think there might now be a few more due to the BOA update:
&lt;/p&gt;
&lt;pre class="wiki"&gt;updatedb
locate xmlrpc.php
/data/all/000/core/drupal-7.23.3/xmlrpc.php
/data/all/000/core/drupal-7.24.1/xmlrpc.php
/data/all/000/core/drupal-7.27.1/xmlrpc.php
/data/all/000/core/drupal-7.28.1/xmlrpc.php
/data/all/000/core/drupal-7.30.1/xmlrpc.php
/data/all/000/core/drupal-7.31.1/xmlrpc.php
/data/all/000/core/pressflow-6.28.3/xmlrpc.php
/data/all/000/core/pressflow-6.29.1/xmlrpc.php
/data/all/000/core/pressflow-6.31.1/xmlrpc.php
/data/all/000/core/pressflow-6.31.2/xmlrpc.php
/data/all/000/core/pressflow-6.32.2/xmlrpc.php
/data/all/000/core/pressflow-6.33.1/xmlrpc.php
/data/disk/tn/aegir/distro/008/xmlrpc.php
/data/disk/tn/aegir/distro/009/xmlrpc.php
/data/disk/tn/aegir/distro/010/xmlrpc.php
/data/disk/tn/aegir/distro/011/xmlrpc.php
/data/disk/tn/aegir/distro/012/xmlrpc.php
/data/disk/tn/distro/008/drupal-7.31.1-prod/xmlrpc.php
/data/disk/tn/distro/008/openatrium-7.x-2.19-7.31.1/xmlrpc.php
/data/disk/tn/platforms/transitionnetwork.org/xmlrpc.php
/data/disk/tn/static/transition-network-d6-33-p001-booker/xmlrpc.php
/data/disk/tn/static/transition-network-d6-33-s001-booker/xmlrpc.php
/var/aegir/host_master/001/xmlrpc.php
/var/aegir/host_master/002/xmlrpc.php
/var/aegir/host_master/003/xmlrpc.php
/var/aegir/host_master/004/xmlrpc.php
/var/aegir/host_master/005/xmlrpc.php
/var/aegir/host_master/006/xmlrpc.php
/var/aegir/host_master/007/xmlrpc.php
/var/aegir/host_master/008/xmlrpc.php
/var/aegir/host_master/009/xmlrpc.php
/var/aegir/host_master/010/xmlrpc.php
/var/aegir/host_master/011/xmlrpc.php
/var/aegir/host_master/012/xmlrpc.php
/var/aegir/host_master/013/xmlrpc.php
/var/aegir/host_master/014/xmlrpc.php
/var/aegir/host_master/015/xmlrpc.php
/var/aegir/host_master/016/xmlrpc.php
/var/aegir/hostmaster-BOA-2.0.4/xmlrpc.php
/var/backups/codebases-cleanup/001/pressflow-6.26.2-dev/xmlrpc.php
/var/backups/codebases-cleanup/001/pressflow-6.26.2-prod/xmlrpc.php
/var/backups/codebases-cleanup/001/pressflow-6.26.2-stage/xmlrpc.php
/var/backups/codebases-cleanup/002/drupal-7.22.1-prod/xmlrpc.php
/var/backups/trash/drupal-7.22.1/xmlrpc.php
&lt;/pre&gt;&lt;p&gt;
I don't know if any of these are available to the public?
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Fri, 08 Aug 2014 08:42:28 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:28</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:28</guid>
      <description>
        &lt;p&gt;
Thanks Chris. I'll investigate ..
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Fri, 08 Aug 2014 09:36:02 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:29</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:29</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.5&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;2.525&lt;/em&gt; to &lt;em&gt;3.025&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
All the sites that are listed on Aegir have had their xmlrpc.php either removed or updated.
&lt;/p&gt;
&lt;p&gt;
However, I had a look over all of the sites and noticed that we have three sites with public domains that are not being updated:
&lt;/p&gt;
&lt;p&gt;
iirs-test.transitionnetwork.org Drupal 7.26
space.transitionnetwork.org Open Atrium 2.0.9 7.24.1 P.004   Drupal 7.24
news.transitionnetwork.org Drupal 6.29
&lt;/p&gt;
&lt;p&gt;
Any thoughts on what should be done with these?  Can any of these be deleted? The latest versions of Drupal are 6.33 &amp;amp; 7.31
&lt;/p&gt;
&lt;p&gt;
I deleted the xmlrpc.php from this ghost platform:
/data/disk/tn/platforms/transitionnetwork.org/xmlrpc.php
&lt;/p&gt;
&lt;p&gt;
I think all of the aegir files are just sitting on the server.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 08 Aug 2014 10:22:34 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:30</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:30</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;3.025&lt;/em&gt; to &lt;em&gt;3.275&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/774#comment:29" title="Comment 29 for Ticket #774"&gt;paul&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
we have three sites with public domains that are not being updated:
&lt;/p&gt;
&lt;p&gt;
iirs-test.transitionnetwork.org Drupal 7.26
space.transitionnetwork.org Open Atrium 2.0.9 7.24.1 P.004   Drupal 7.24
news.transitionnetwork.org Drupal 6.29
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Well spotted!
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://news.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://news.transitionnetwork.org/&lt;/a&gt; this is in use and as far as I'm aware should be updated, best check with Ed. The ticket on which it was migrated to &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;PuffinServer&lt;/a&gt; is &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/480" title="defect: Transfer news.TN.org to puffin (closed: fixed)"&gt;ticket:480&lt;/a&gt;, I would guess that it's code is in a git repo, perhaps use Drush to get a admin login to the site and check the status to start with?
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://space.transitionnetwork.org/home"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://space.transitionnetwork.org/home&lt;/a&gt; this is a non-public site that Jim set up for Ed, I think it wasn't used, best check with Ed if it is needed. If it is then upgrading it should be straight forward as it shouldn't have many, (or any) plugins.
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://iirs-test.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://iirs-test.transitionnetwork.org/&lt;/a&gt; I don't know if Jim or Annesley set that up, best check with Ed and Annesley.
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Fri, 08 Aug 2014 11:02:34 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:31</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:31</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.125&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;3.275&lt;/em&gt; to &lt;em&gt;3.4&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
For &lt;a class="ext-link" href="http://news.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://news.transitionnetwork.org/&lt;/a&gt;  I just need to migrate it to the new production platform. I'll do that now ..
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Fri, 08 Aug 2014 11:04:35 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:32</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:32</guid>
      <description>
        &lt;p&gt;
I'll migrate to stage first ..
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Fri, 08 Aug 2014 11:27:12 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:33</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:33</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;3.4&lt;/em&gt; to &lt;em&gt;3.65&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
​&lt;a class="ext-link" href="http://news.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://news.transitionnetwork.org/&lt;/a&gt;  is now updated to the latest production platform &amp;amp; we now have a clone of this site on a stage platfrom. Looking now into &lt;a class="ext-link" href="https://space.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://space.transitionnetwork.org/&lt;/a&gt; ..
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Fri, 08 Aug 2014 11:52:51 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:34</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:34</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;3.65&lt;/em&gt; to &lt;em&gt;3.9&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Theres appears to  be nothing documented about openatrium on the wiki / trac.
&lt;/p&gt;
&lt;p&gt;
The current version of the open atrium site is here:
&lt;/p&gt;
&lt;p&gt;
puffin:/data/disk/tn/distro/004/openatrium-7.x-2.09-7.24.1# ls -la
total 592K
drwxr-xr-x 4 tn     users    4.0K Aug  7 19:09 ./
drwx--x--x 5 tn     users    4.0K Nov 30  2013 ../
lrwxrwxrwx 1 tn     users      46 Nov 30  2013 authorize.php -&amp;gt; /data/all/000/core/drupal-7.24.1/authorize.php
drwxrwsr-x 2 tn.ftp www-data 4.0K Jan 13  2014 cache/
lrwxrwxrwx 1 tn     users      41 Nov 30  2013 cron.php -&amp;gt; /data/all/000/core/drupal-7.24.1/cron.php
lrwxrwxrwx 1 tn     users      48 Nov 30  2013 crossdomain.xml -&amp;gt; /data/all/000/core/drupal-7.24.1/crossdomain.xml
-r--r--r-- 1 tn     users    573K Aug  7 23:13 drushrc.php
lrwxrwxrwx 1 tn     users      42 Nov 30  2013 .htaccess -&amp;gt; /data/all/000/core/drupal-7.24.1/.htaccess
lrwxrwxrwx 1 tn     users      41 Nov 30  2013 includes -&amp;gt; /data/all/000/core/drupal-7.24.1/includes/
lrwxrwxrwx 1 tn     users      42 Nov 30  2013 index.php -&amp;gt; /data/all/000/core/drupal-7.24.1/index.php
lrwxrwxrwx 1 tn     users      44 Nov 30  2013 install.php -&amp;gt; /data/all/000/core/drupal-7.24.1/install.php
lrwxrwxrwx 1 root   root       39 May  1 16:25 js.php -&amp;gt; /data/all/005/o_contrib_seven/js/js.php
lrwxrwxrwx 1 tn     users      37 Nov 30  2013 misc -&amp;gt; /data/all/000/core/drupal-7.24.1/misc/
lrwxrwxrwx 1 tn     users      40 Nov 30  2013 modules -&amp;gt; /data/all/000/core/drupal-7.24.1/modules/
lrwxrwxrwx 1 tn     users      49 Nov 30  2013 profiles -&amp;gt; /data/all/004/openatrium-7.x-2.09-7.24.1/profiles/
drwxr-x--x 5 tn     users    4.0K Jan 12  2014 sites/
lrwxrwxrwx 1 tn     users      39 Nov 30  2013 themes -&amp;gt; /data/all/000/core/drupal-7.24.1/themes/
lrwxrwxrwx 1 tn     users      43 Nov 30  2013 update.php -&amp;gt; /data/all/000/core/drupal-7.24.1/update.php
lrwxrwxrwx 1 tn     users      43 Nov 30  2013 web.config -&amp;gt; /data/all/000/core/drupal-7.24.1/web.config
&lt;/p&gt;
&lt;p&gt;
We need to be using:
&lt;/p&gt;
&lt;p&gt;
/data/disk/tn/distro/008/openatrium-7.x-2.19-7.31.
&lt;/p&gt;
&lt;p&gt;
I'll see if I can build a new openatrium platform with Aegir ..
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Fri, 08 Aug 2014 11:56:31 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:35</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:35</guid>
      <description>
        &lt;p&gt;
This latest openatrium platform is automatically built by Aegir. I'll migrate the openatrium site to the new platform ..
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 08 Aug 2014 11:59:30 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:36</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:36</guid>
      <description>
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/774#comment:34" title="Comment 34 for Ticket #774"&gt;paul&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Theres appears to  be nothing documented about openatrium on the wiki / trac.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
There are a couple of tickets:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/560" title="enhancement: Install drupal-based project management system onto our servers (closed: fixed)"&gt;ticket:560&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="assigned ticket" href="http://localhost:8080/trac/ticket/636" title="task: Changes to Space.transitionnetwork.org homepage to facilitate user ... (assigned)"&gt;ticket:636&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
There might be some others.
&lt;/p&gt;
&lt;p&gt;
Perhaps Jim didn't get around to documenting it further than this?
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Fri, 08 Aug 2014 12:14:06 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:37</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:37</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;3.9&lt;/em&gt; to &lt;em&gt;4.15&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Thanks Chris. I'll take a look a these shortly.
&lt;/p&gt;
&lt;p&gt;
@TN
&lt;/p&gt;
&lt;p&gt;
Openatium is now updated.
&lt;/p&gt;
&lt;p&gt;
I'll take a look at IIRs shortly.
&lt;/p&gt;
&lt;p&gt;
I'll also see what platforms can be deleted from Aegir - platforms that are no longer being used as the site(s) that once ran on them have been migrated to a more recent version of the platform
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Fri, 08 Aug 2014 13:09:17 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:38</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:38</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.5&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;4.15&lt;/em&gt; to &lt;em&gt;4.65&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
The IIRs site is built manually without an external platform file, and outside of version control. It's currently running drupal 7.26 and a collection of modules.
&lt;/p&gt;
&lt;p&gt;
@ Annesley
&lt;/p&gt;
&lt;p&gt;
I have put the site into maintenance mode for now as the site needs to be upgraded.  Any thoughts on what to do next?
&lt;/p&gt;
&lt;p&gt;
I have deleted platform / sites that are no longer needed - but have retained the previous version of the platform just in case we need to migrate back to the previous version of the site.
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://tn.puffin.webarch.net/hosting/sites"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://tn.puffin.webarch.net/hosting/sites&lt;/a&gt;
&lt;a class="ext-link" href="https://tn.puffin.webarch.net/hosting/platforms"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://tn.puffin.webarch.net/hosting/platforms&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Everything we can do now - to keep our sites/server secure - has been done.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>annesley</dc:creator>

      <pubDate>Mon, 11 Aug 2014 07:45:29 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:39</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:39</guid>
      <description>
        &lt;p&gt;
hi! iirs-test is nothing to do with me.
&lt;/p&gt;
&lt;p&gt;
i am using an enabled IIRS Module on booker staging &lt;a class="ext-link" href="https://booker-stage-20140717.transitionnetwork.org/IIRS/registration/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://booker-stage-20140717.transitionnetwork.org/IIRS/registration/&lt;/a&gt;
which appears to have disappeared. but i am developing locally so can copy it back no problem.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Mon, 11 Aug 2014 08:42:05 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:40</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:40</guid>
      <description>
        &lt;ol&gt;&lt;li&gt;IIRS-test on D7 is Jim's old work and can be removed
&lt;/li&gt;&lt;li&gt;Open Atrium was set up as a trial intranet, got picked up by the international team before we'd trialled it, I'm not sure how much it's being used now, finding out is on my agenda
&lt;/li&gt;&lt;li&gt;news.transitionnetwork.org is a news feed aggregator which collects news feeds from TI sites and re-publishes teasers of them on that domain, and into the TI profile pages. It is one of the services that will be de-commissioned this autumn
&lt;/li&gt;&lt;/ol&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Mon, 11 Aug 2014 09:42:59 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:41</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:41</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.125&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;4.65&lt;/em&gt; to &lt;em&gt;4.775&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/774#comment:40" title="Comment 40 for Ticket #774"&gt;ed&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;ol&gt;&lt;li&gt;IIRS-test on D7 is Jim's old work and can be removed
&lt;/li&gt;&lt;/ol&gt;&lt;/blockquote&gt;
&lt;p&gt;
I'll remove now ..
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;ol start="2"&gt;&lt;li&gt;Open Atrium was set up as a trial intranet, got picked up by the international team before we'd trialled it, I'm not sure how much it's being used now, finding out is on my agenda
&lt;/li&gt;&lt;/ol&gt;&lt;/blockquote&gt;
&lt;p&gt;
Maybe we could trial the software as a basecamp tool while bulding the IIRS?
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;ol start="3"&gt;&lt;li&gt;news.transitionnetwork.org is a news feed aggregator which collects news feeds from TI sites and re-publishes teasers of them on that domain, and into the TI profile pages. It is one of the services that will be de-commissioned this autumn
&lt;/li&gt;&lt;/ol&gt;&lt;/blockquote&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Mon, 11 Aug 2014 09:51:39 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:42</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:42</guid>
      <description>
        &lt;ol&gt;&lt;li&gt;Good
&lt;/li&gt;&lt;li&gt;Interesting. The national hubs found it cumbersome and it looked like we'd need to do more work to really get it sorted. Staff are about to move to google apps lock stock and barrel I reckon (and now recommend). Tech: atm we're using the wiki pages and emails as agreed. I'm interested in using a use case based tool for TNv3, and not particularly ingterested in doing any dev work on OA.
&lt;/li&gt;&lt;li&gt;Good.
&lt;/li&gt;&lt;/ol&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Mon, 11 Aug 2014 09:59:51 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/774#comment:43</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:43</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.125&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;4.775&lt;/em&gt; to &lt;em&gt;4.9&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/774#comment:42" title="Comment 42 for Ticket #774"&gt;ed&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;ol&gt;&lt;li&gt;Good
&lt;/li&gt;&lt;/ol&gt;&lt;/blockquote&gt;
&lt;p&gt;
The IIRS site and platform have now been deleted.
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;ol start="2"&gt;&lt;li&gt;Interesting. The national hubs found it cumbersome and it looked like we'd need to do more work to really get it sorted. Staff are about to move to google apps lock stock and barrel I reckon (and now recommend). Tech: atm we're using the wiki pages and emails as agreed. I'm interested in using a use case based tool for TNv3, and not particularly ingterested in doing any dev work on OA.
&lt;/li&gt;&lt;li&gt;Good.
&lt;/li&gt;&lt;/ol&gt;&lt;/blockquote&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 11 Aug 2014 12:38:06 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:44</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:44</guid>
      <description>
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/774#comment:42" title="Comment 42 for Ticket #774"&gt;ed&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Staff are about to move to google apps lock stock and barrel I reckon (and now recommend).
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Choosing to becoming dependant on one of the planets biggest imperial corporations &lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt; for internal communications and documentation, when there are Free/libre alternatives which can be self hosted, is not the way to be resilient and autonomous.
&lt;/p&gt;
&lt;p&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt; &lt;a class="ext-link" href="https://www.wikileaks.org/Op-ed-The-Banality-of-Don-t-Be.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.wikileaks.org/Op-ed-The-Banality-of-Don-t-Be.html&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>annesley</dc:creator>

      <pubDate>Mon, 11 Aug 2014 13:08:46 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:45</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:45</guid>
      <description>
        &lt;p&gt;
@Chris: do you accept the cost-benefit-politics suggestion?
do you agree that we cannot be perfect politically? and that it's a matter of where we draw the line, not a binary decision?
&lt;/p&gt;
&lt;p&gt;
so, to use an extreme to illustrate the point: if it cost £200,000 / year to avoid using Google and install Free/libre alternatives would you agree that we should use Google?
&lt;/p&gt;
&lt;p&gt;
don't think that i am not with you. i am. i totally reject Capitalism, hierarchy, elites, consumption, etc. but i want you to join us in trying to calculate where to draw the line, instead of repeating this binary idea. Transition lives in Capitalism and it doesn't have endless money. decisions must be made. we cannot run our own copy of the Internet because the Cobolt used in the intermediate machines is mined in oppressive conditions for example.
&lt;/p&gt;
&lt;p&gt;
i think the essential problem here is the fact is that IT software has massive economies of scale. so trying to implement things individually is always going to empty the pockets of the very organisations that are trying to defeat Capitalism.
&lt;/p&gt;
&lt;p&gt;
how much does it cost to run these alternatives? and train people, and maintain them? give us an estimate for a year period.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Mon, 11 Aug 2014 13:11:02 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:46</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:46</guid>
      <description>
        &lt;p&gt;
@Annesley and @Chris - conversations about TN's decisions around intranet software are &lt;strong&gt;out of scope&lt;/strong&gt; here.
&lt;/p&gt;
&lt;p&gt;
Please do not pursue this conversation on this ticket or on TN time. Please feel free to enjoy it down the pub however :)
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Mon, 11 Aug 2014 13:16:19 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:47</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:47</guid>
      <description>
        &lt;p&gt;
@TN
&lt;/p&gt;
&lt;p&gt;
Sorry off topic ..
&lt;/p&gt;
&lt;p&gt;
What libre alternatives were considered before choosing Google?
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Mon, 11 Aug 2014 13:18:11 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/774#comment:48</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:48</guid>
      <description>
        &lt;p&gt;
@Paul happy to discuss this with you in your time at another time when I'm not doing other stuff
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>ed</dc:creator>

      <pubDate>Mon, 08 Sep 2014 12:56:45 GMT</pubDate>
      <title>status changed; resolution set</title>
      <link>http://localhost:8080/trac/ticket/774#comment:49</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/774#comment:49</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Closing this ticket for now as before we got side tracked Paul said 'Everything we can do now - to keep our sites/server secure - has been done.'
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://trac.transitionnetwork.org/trac/ticket/774#comment:38"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://trac.transitionnetwork.org/trac/ticket/774#comment:38&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>