<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #891: Issue with TTT and REconomy websites after upgrade to WP 4.4</title>
    <link>http://localhost:8080/trac/ticket/891</link>
    <description>&lt;p&gt;
Email from Laura:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Just to let you know there's a bit of an oddity going on with both the TTT and
Reconomy websites.
&lt;/p&gt;
&lt;p&gt;
I upgraded to WP 4.4 after running full tests on my local copies here, and for
some odd reason images aren't showing on the site.  If you try to open an
image in the browser eg
&lt;a class="ext-link" href="https://www.reconomy.org/wp-content/uploads/2015/10/hubs-logos-landscape.jpg"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.reconomy.org/wp-content/uploads/2015/10/hubs-logos-landscape.jpg&lt;/a&gt;
takes you to the -
"Server error!
The server encountered an internal error and was unable to complete your
request
Either the server is overloaded or there was an error in a CGI script.
Please return to the front page of the site."
&lt;/p&gt;
&lt;p&gt;
I've updated over 20 sites over the past few days (!) and these are the only
two this has happened on.
There are a few discussions here, (and have tried the temp fix of various
functions.php tweaks in the theme files to see if that helps, but it
doesn't)...
&lt;a class="ext-link" href="https://wordpress.org/support/topic/after-upgrade-to-44-media-files-are-not-showing"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wordpress.org/support/topic/after-upgrade-to-44-media-files-are-not-showing&lt;/a&gt;
and even though sites are not appearing to use SSL wondering if related
somehow to that or other? Has this happened to any other WP 4.4 sites on your
servers?
&lt;/p&gt;
&lt;p&gt;
I'll let TTT and REconomy know their site has been updated, but there is a
glitch at present.
&lt;/p&gt;
&lt;p&gt;
I've also added Wordfence to the sites too as there are swathes of brute force
attacks happening on lots of WP sites everywhere currently and this plugin
seems to help somewhat currently.  I don't think it's the Wordfence plugin, as
disabled it to test the missing images issue.
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/891</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Thu, 17 Dec 2015 11:26:12 GMT</pubDate>
      <title>attachment set</title>
      <link>http://localhost:8080/trac/ticket/891</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/891</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;attachment&lt;/strong&gt;
                set to &lt;em&gt;reconomy.png&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Thu, 17 Dec 2015 11:28:18 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/891#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/891#comment:1</guid>
      <description>
        &lt;p&gt;
Hi Laura
&lt;/p&gt;
&lt;p&gt;
The site looks OK to me (see screenshot)
&lt;/p&gt;
&lt;p&gt;
I can also access the image here: &lt;a class="ext-link" href="https://www.reconomy.org/wp-content/uploads/2015/10/hubs-logos-landscape.jpg"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.reconomy.org/wp-content/uploads/2015/10/hubs-logos-landscape.jpg&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
It looks OK from New York too: &lt;a class="ext-link" href="http://tools.pingdom.com/fpt/#!/bVVveJ/www.reconomy.org"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://tools.pingdom.com/fpt/#!/bVVveJ/www.reconomy.org&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
So could it be a proxy or cache on your local machine that's playing up?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 17 Dec 2015 11:51:06 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/891#comment:2</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/891#comment:2</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.5&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.5&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Replying to &lt;a href="http://localhost:8080/trac/ticket/891#comment:1" title="Comment 1 for Ticket #891"&gt;sam&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
The site looks OK to me (see screenshot)
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
I fixed it before you looked at it by the sounds of it!
&lt;/p&gt;
&lt;p&gt;
Replying to &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/891" title="maintenance: Issue with TTT and REconomy websites after upgrade to WP 4.4 (closed: fixed)"&gt;chris&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I've also added Wordfence to the sites too as there are swathes of brute force
attacks happening on lots of WP sites everywhere currently and this plugin
seems to help somewhat currently.  I don't think it's the Wordfence plugin, as
disabled it to test the missing images issue.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/blockquote&gt;
&lt;p&gt;
It was this file that Wordfence created, &lt;tt&gt;/home/reconomy/sites/default/  .htaccess&lt;/tt&gt; that contained:
&lt;/p&gt;
&lt;pre class="wiki"&gt;# BEGIN Wordfence code execution protection
&amp;lt;IfModule mod_php5.c&amp;gt;
php_flag engine 0
&amp;lt;/IfModule&amp;gt;
AddHandler cgi-script .php .phtml .php3 .pl .py .jsp .asp .htm .shtml .sh .cgi
Options -ExecCGI
# END Wordfence code execution protection
&lt;/pre&gt;&lt;p&gt;
The Apache config doesn't allow &lt;tt&gt;Options&lt;/tt&gt; so if we want to disable php from running in the &lt;tt&gt;wp-content/uploads/&lt;/tt&gt; directory (which is a good idea) we need to edit the templates used to generate the Apache config, I have now done this and rebuilt the Apache config for all &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; sites.
&lt;/p&gt;
&lt;p&gt;
I agree regarding the brute force attacks, what I have been doing elsewhere is using fail2ban, I have suggested we install this, see &lt;a class="new ticket" href="http://localhost:8080/trac/ticket/871" title="maintenance: Brute Force Attacks Against WordPress Sites (new)"&gt;ticket:871&lt;/a&gt; and &lt;a class="new ticket" href="http://localhost:8080/trac/ticket/851" title="maintenance: Bot attacks on Transition Culture (new)"&gt;ticket:851&lt;/a&gt; and I said in &lt;a class="new ticket" href="http://localhost:8080/trac/ticket/887#comment:1" title="maintenance: Lot's of failed logins on conference15.transitionnetwork.org (new)"&gt;ticket:887#comment:1&lt;/a&gt;
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I'd very much like to rebuild &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;ParrotServer&lt;/a&gt; with a newer version of Debian and the Webarchitects hosting scripts as these support &lt;a class="ext-link" href="https://www.letsencrypt.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Let's Encrypt&lt;/a&gt;, &lt;a class="ext-link" href="https://www.piwik.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Piwik&lt;/a&gt; (adding accounts and installing the wp-piwik plugin automatically), the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; &lt;tt&gt;stop-xmlrpc-attack&lt;/tt&gt; plugin and also &lt;tt&gt;fail2ban&lt;/tt&gt; for &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; and phpMyAdmin, see also &lt;a class="new ticket" href="http://localhost:8080/trac/ticket/875" title="maintenance: Free HTTPS certificates from Let's Encrypt (new)"&gt;ticket:875&lt;/a&gt; and &lt;a class="new ticket" href="http://localhost:8080/trac/ticket/851" title="maintenance: Bot attacks on Transition Culture (new)"&gt;ticket:851&lt;/a&gt;.
&lt;/p&gt;
&lt;/blockquote&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 17 Dec 2015 12:11:32 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/891#comment:3</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/891#comment:3</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.15&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.5&lt;/em&gt; to &lt;em&gt;0.65&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
I have also edited, &lt;tt&gt;/wp-content/uploads/delightful-downloads/.htaccess&lt;/tt&gt; for both sites to comment out:
&lt;/p&gt;
&lt;pre class="wiki"&gt;#Options -Indexes
deny from all
&lt;/pre&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>laura</dc:creator>

      <pubDate>Thu, 17 Dec 2015 18:06:18 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/891#comment:4</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/891#comment:4</guid>
      <description>
        &lt;p&gt;
Just a quick note to say thanks Chris for fixing, happy for other plugins such as fail2ban (not used as yet) to be added.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Wed, 28 Sep 2016 13:03:32 GMT</pubDate>
      <title>cc, status changed</title>
      <link>http://localhost:8080/trac/ticket/891#comment:5</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/891#comment:5</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;cc&lt;/strong&gt;
              &lt;em&gt;laura&lt;/em&gt; removed
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;assigned&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Wed, 28 Sep 2016 13:08:25 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/891#comment:6</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/891#comment:6</guid>
      <description>
        &lt;p&gt;
Hi Chris
&lt;/p&gt;
&lt;p&gt;
We've just spotted that all the images &amp;amp; files seem to have disappeared from the Reconomy site.
&lt;/p&gt;
&lt;p&gt;
I've just tried re-uploading an image and that doesn't seem to work. In the frontend it seems to upload &amp;amp; generates a URL for it: &lt;a class="ext-link" href="http://www.reconomy.org/wp-content/uploads/2016/09/TransitionFollowerKeywords.png"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.reconomy.org/wp-content/uploads/2016/09/TransitionFollowerKeywords.png&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
But it gives a:
Server error!
The server encountered an internal error and was unable to complete your request
Either the server is overloaded or there was an error in a CGI script.
&lt;/p&gt;
&lt;p&gt;
I do have backups that I could restore from, but I was just wondering if you had any thoughts on why this might have happened?
&lt;/p&gt;
&lt;p&gt;
Googling it suggests it might be a htaccess thing? But I don't suppose you've made any changes to that recently?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Wed, 28 Sep 2016 13:17:46 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/891#comment:7</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/891#comment:7</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.15&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.65&lt;/em&gt; to &lt;em&gt;0.8&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Hi, fixed, it was the same issue as before, this was the error in &lt;tt&gt;~/logs/error.log&lt;/tt&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;[Wed Sep 28 14:08:38 2016] [alert] [client XX.XX.XX.XX] /home/reconomy/sites/default/wp-content/uploads/.htaccess: php_flag not allowed here
&lt;/pre&gt;&lt;p&gt;
So I edited that file to comment out the disallowed lines:
&lt;/p&gt;
&lt;pre class="wiki"&gt;# BEGIN Wordfence code execution protection
#&amp;lt;IfModule mod_php5.c&amp;gt;
#php_flag engine 0
#&amp;lt;/IfModule&amp;gt;
#&amp;lt;IfModule mod_php7.c&amp;gt;
#php_flag engine 0
#&amp;lt;/IfModule&amp;gt;
AddHandler cgi-script .php .phtml .php3 .pl .py .jsp .asp .htm .shtml .sh .cgi
#Options -ExecCGI
# END Wordfence code execution protection
&lt;/pre&gt;&lt;p&gt;
I have also edited the template that generates the Apache config to make it more permissive:
&lt;/p&gt;
&lt;pre class="wiki"&gt;  #AllowOverride AuthConfig Indexes FileInfo Limit
  AllowOverride ALL
&lt;/pre&gt;&lt;p&gt;
And rebuilt the config.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Wed, 28 Sep 2016 13:28:44 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/891#comment:8</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/891#comment:8</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.8&lt;/em&gt; to &lt;em&gt;0.9&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
I have re-edited the &lt;tt&gt;/home/reconomy/sites/default/wp-content/uploads/.htaccess&lt;/tt&gt; file back to how it was originally:
&lt;/p&gt;
&lt;pre class="wiki"&gt;# BEGIN Wordfence code execution protection
&amp;lt;IfModule mod_php5.c&amp;gt;
php_flag engine 0
&amp;lt;/IfModule&amp;gt;
&amp;lt;IfModule mod_php7.c&amp;gt;
php_flag engine 0
&amp;lt;/IfModule&amp;gt;
AddHandler cgi-script .php .phtml .php3 .pl .py .jsp .asp .htm .shtml .sh .cgi
Options -ExecCGI
# END Wordfence code execution protection
&lt;/pre&gt;&lt;p&gt;
And tested the image and it all seems fine.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Wed, 28 Sep 2016 13:30:10 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/891#comment:9</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/891#comment:9</guid>
      <description>
        &lt;p&gt;
In terms of how it happened -- a &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; plugin will have updated the &lt;tt&gt;.htaccess&lt;/tt&gt; file and caused it, but it won't happen again as the directives not allowed before are now allowed.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Wed, 28 Sep 2016 13:32:21 GMT</pubDate>
      <title>status changed; resolution set</title>
      <link>http://localhost:8080/trac/ticket/891#comment:10</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/891#comment:10</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;assigned&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Great, thanks Chris.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>laura</dc:creator>

      <pubDate>Wed, 28 Sep 2016 19:52:46 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/891#comment:11</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/891#comment:11</guid>
      <description>
        &lt;p&gt;
Hi Chris and Sam
Just to let you know, that Reconomy didn't update their maintenance contract with me this year and I haven't touched their site since &lt;a class="missing wiki"&gt;Jan/Feb?&lt;/a&gt;, so I possibly don't need to be added to the ticket (I still do periodic updates on the TTT site as and when they need me) ...Wordfence (and WP core) may be set to auto update upon release or they/you may be running the updates now with the Wordfence one causing this issue every so often.
Best Laura
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Wed, 28 Sep 2016 20:04:02 GMT</pubDate>
      <title>cc changed</title>
      <link>http://localhost:8080/trac/ticket/891#comment:12</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/891#comment:12</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;cc&lt;/strong&gt;
              &lt;em&gt;laura&lt;/em&gt; added; &lt;em&gt;ade&lt;/em&gt; removed
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Hi Laura, The TTT sites are now running on Webarchitects shared hosting and if they use the same plugin they might also hit this issue, let me know via a direct email if you need the SFTP login for these sites, or get them from admin@….
&lt;/p&gt;
&lt;p&gt;
Also it is perhaps worth noting that although this Wordfence &lt;tt&gt;.htaccess&lt;/tt&gt; files is designed to make the site safer, we already have rules that cover this in the main Apache config and by not allowing some directives in &lt;tt&gt;.htaccess&lt;/tt&gt; files it makes the server more secure, so the edit I did to allow the Wordfence &lt;tt&gt;.htaccess&lt;/tt&gt; file makes things less secure, this isn't something we would do on our shared servers...
&lt;/p&gt;
&lt;p&gt;
In terms of the Reconony site, I'm clueless what the plan is for it or where or when it is due to move, but someday the server it is running on is due to be shutdown, but again I have no idea when, see &lt;a class="new ticket" href="http://localhost:8080/trac/ticket/924" title="maintenance: Sheffield Server Shutdown Timetable? (new)"&gt;ticket:924&lt;/a&gt;.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>laura</dc:creator>

      <pubDate>Wed, 28 Sep 2016 20:11:58 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/891#comment:13</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/891#comment:13</guid>
      <description>
        &lt;p&gt;
Hi Chris
I hope all is well, yes, the TTT site needs an update of the word fence plugin as I've had an email notification saying there's an update available from their site notifications come through today (I'm not sure if TTT's is set to auto update or not 24 hours after coming available). Happy to remove word fence on TTT if not needed from your perspective. I have no news on plans or not for REconomy, the person who took over from Fi was going to get in touch at the start of the year but never did, so haven't been managing that site.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>