On Thu, 31 Mar 2005 01:23:56 +1000, Tim Starling
<t.starling(a)physics.unimelb.edu.au> wrote:
David Gerard wrote:
Has anyone had a chance to look at bug 550?
It's specifically so that this
sort of block will only hit anon users.
I've told the list before that the spammers already have software to log
in to wikis, and the vandals log in whenever it's convenient for them.
In a previous post, I even gave details of vandalbot attacks by logged
in users. But I guess you won't believe me that it's useless until you
see it. I already had an exemption in place for non-newbies, I've
replaced this with an exemption for all logged-in users.
Tim please don't. We already had a bot page move attacked on sq: (from
[[w:sq:User:Biskota]]). I happened to be online at the time (only two
admins on sq, about 5 regular users), and still it took me and another
contributor a good 20 minutes to clean up all the page moves. If I
hadn't been online the only good way to fix it would have been a db
restore. We were also lucky that it wasn't using a proxy, but it's the
next logical step for an attacker.
Page move and edit throttling for newbie users would also be
tremendously useful (maybe it can be put in 1.5 since the schema is
changing).