<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://forums.movabletype.org/2008/05/hacker-activity-in-activity-lo.html" />
  <link rel="self" type="application/atom+xml" href="http://forums.movabletype.org/atom.xml" />
  <id>tag:forums.movabletype.org,2011://24/tag:www.movabletype.org,2008:/documentation//1.6226-</id>
  <updated>2011-09-01T02:28:22Z</updated>
  <title>Comments for Hacker activity in Activity Log?</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.292</generator>
  <entry>
    <id>tag:www.movabletype.org,2008:/documentation//1.6226</id>
    <link rel="alternate" type="text/html" href="http://forums.movabletype.org/2008/05/hacker-activity-in-activity-lo.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.movabletype.org/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=24/entry_id=6226" title="Hacker activity in Activity Log?" />
    <published>2008-05-26T18:29:24Z</published>
    <updated>2008-05-30T06:59:29Z</updated>
    <title>Hacker activity in Activity Log?</title>
    <summary>I just noticed this morning that I have been getting strange activity in my Activity Log. There are several entries that look like this (it&apos;s the Dutch version, translation followe): Update van geplande taken (IP: 24.14.223.183) YWAM Europe 24.14.223.183 12...</summary>
    <author>
      <name>Rodney Blevins</name>
      <uri>http://blevins.nl</uri>
    </author>
    
    <category term="Movable Type" />
    
    <content type="html" xml:lang="en" xml:base="http://forums.movabletype.org/">
      <![CDATA[<p>I just noticed this morning that I have been getting strange activity in my Activity Log.</p>

<p>There are several entries that look like this (it's the Dutch version, translation followe):</p>

<blockquote>
Update van geplande taken (IP: 24.14.223.183)   YWAM Europe 24.14.223.183   12 minutes ago

Volgende taken moesten uitgevoerd worden: Vervaldatum spam-map
</blockquote>

<p>Which translated to "Update to planned tasks", IP, blog name, etc. and then:
"The following tasks should be carried out: Spam folder expiration date"</p>

<p>Does anyone know what this is?  Has anyone else had this?  It makes me think that someone is trying to hack my blog to allow spam in some way.</p>
]]>
      

    </content>
  </entry>

  <entry>
    <id>tag:www.movabletype.org,2008:/documentation//1.6226-comment:5058</id>
    <thr:in-reply-to ref="tag:www.movabletype.org,2008:/documentation//1.6226" type="text/html" href="http://forums.movabletype.org/2008/05/hacker-activity-in-activity-lo.html"/>
    <link rel="alternate" type="text/html" href="http://forums.movabletype.org/2008/05/hacker-activity-in-activity-lo.html#c5058" />
    <title>Comment from Byrne Reese on 2008-05-29</title>
    <author>
        <name>Byrne Reese</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>This is almost certainly *not* a hacker attack. It looks as if a task is failing for some reason.</p>

<p>What is the category or type of log entry for this record in your activity log? Is it an error record or something else?</p>]]>
    </content>
    <published>2008-05-29T23:55:43Z</published>
  </entry>

  <entry>
    <id>tag:www.movabletype.org,2008:/documentation//1.6226-comment:5059</id>
    <thr:in-reply-to ref="tag:www.movabletype.org,2008:/documentation//1.6226" type="text/html" href="http://forums.movabletype.org/2008/05/hacker-activity-in-activity-lo.html"/>
    <link rel="alternate" type="text/html" href="http://forums.movabletype.org/2008/05/hacker-activity-in-activity-lo.html#c5059" />
    <title>Comment from Byrne Reese on 2008-05-29</title>
    <author>
        <name>Byrne Reese</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>According to Brad Choate, "that's just a normal system message. the 'The following tasks were run: ...'"</p>]]>
    </content>
    <published>2008-05-29T23:56:24Z</published>
  </entry>

  <entry>
    <id>tag:www.movabletype.org,2008:/documentation//1.6226-comment:5071</id>
    <thr:in-reply-to ref="tag:www.movabletype.org,2008:/documentation//1.6226" type="text/html" href="http://forums.movabletype.org/2008/05/hacker-activity-in-activity-lo.html"/>
    <link rel="alternate" type="text/html" href="http://forums.movabletype.org/2008/05/hacker-activity-in-activity-lo.html#c5071" />
    <title>Comment from Rodney Blevins on 2008-05-29</title>
    <author>
        <name>Rodney Blevins</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Thanks for your reply.  I didn't think the message had been published, since I got an MT error about custom fields or something when I tried to post.  I tried it three times, so I may have posted this message several times.</p>

<p>I contacted support about it and got pretty much the same message.</p>

<p>The only strange thing is, that the IP addresses are all different and none of them are related to me or to the website in anyway.  It was probably just some bot crawling through the site.  On the other hand, that bot would have had to know about the scheduled tasks script, wouldn't it?  Therefore it seems to me like it was a deliberate visit to the scheduled tasks script.</p>

<p>Anyway, I'm not worried about it, but it does seem strange.  I just hope that no code can be injected into the scheduled tasks script and run on my system.  Is there anyway I can see all the planned tasks in one list?</p>]]>
    </content>
    <published>2008-05-30T06:59:29Z</published>
  </entry>

</feed>

