Or simply a user configurable limit of being able to only create 1 user per ip per hour.
That would stop excessive user creation into the hundreds from an IP.
-----Original Message----- From: mediawiki-l-bounces@Wikimedia.org [mailto:mediawiki-l-bounces@Wikimedia.org] On Behalf Of GraphoPhile Sent: 12 October 2005 09:24 To: mediawiki-l@Wikimedia.org Subject: [Mediawiki-l] Delete passive users ?
Jani : Does this not provide a fine attack against Mediawikis: make a bot that generates and register users. After some trillions of random users added the wiki is on its knees. GP : From Rob answer I understood that the problem is for links that are created in the system when a user is active. If a bot "just" adds trillions of users I guess he's got no time for creating pages. So these passive users could be erased ??????? The need is of an alarm indicator of "over registration of users".
_______________________________________________ MediaWiki-l mailing list MediaWiki-l@Wikimedia.org http://mail.wikipedia.org/mailman/listinfo/mediawiki-l
****************************************** The information contained in, or attached to, this e-mail, may contain confidential information and is intended solely for the use of the individual or entity to whom they are addressed and may be subject to legal privilege. If you have received this e-mail in error you should notify the sender immediately by reply e-mail, delete the message from your system and notify your system manager. Please do not copy it for any purpose, or disclose its contents to any other person. The views or opinions presented in this e-mail are solely those of the author and do not necessarily represent those of the company. The recipient should check this e-mail and any attachments for the presence of viruses. The company accepts no liability for any damage caused, directly or indirectly, by any virus transmitted in this email. ******************************************
And what about an email verification ? An account is marked to be deleted if not verfied by email after 24h (needs a bot to do that) :)
E.
-----Message d'origine----- De : mediawiki-l-bounces@Wikimedia.org [mailto:mediawiki-l-bounces@Wikimedia.org] De la part de Thompson, Graeme (AELE) Envoyé : mercredi 12 octobre 2005 10:56 À : MediaWiki announcements and site admin list Objet : RE: [Mediawiki-l] Delete passive users ?
Or simply a user configurable limit of being able to only create 1 user per ip per hour.
That would stop excessive user creation into the hundreds from an IP.
-----Original Message----- From: mediawiki-l-bounces@Wikimedia.org [mailto:mediawiki-l-bounces@Wikimedia.org] On Behalf Of GraphoPhile Sent: 12 October 2005 09:24 To: mediawiki-l@Wikimedia.org Subject: [Mediawiki-l] Delete passive users ?
Jani : Does this not provide a fine attack against Mediawikis: make a bot that generates and register users. After some trillions of random users added the wiki is on its knees. GP : From Rob answer I understood that the problem is for links that are created in the system when a user is active. If a bot "just" adds trillions of users I guess he's got no time for creating pages. So these passive users could be erased ??????? The need is of an alarm indicator of "over registration of users".
_______________________________________________ MediaWiki-l mailing list MediaWiki-l@Wikimedia.org http://mail.wikipedia.org/mailman/listinfo/mediawiki-l
****************************************** The information contained in, or attached to, this e-mail, may contain confidential information and is intended solely for the use of the individual or entity to whom they are addressed and may be subject to legal privilege. If you have received this e-mail in error you should notify the sender immediately by reply e-mail, delete the message from your system and notify your system manager. Please do not copy it for any purpose, or disclose its contents to any other person. The views or opinions presented in this e-mail are solely those of the author and do not necessarily represent those of the company. The recipient should check this e-mail and any attachments for the presence of viruses. The company accepts no liability for any damage caused, directly or indirectly, by any virus transmitted in this email. ****************************************** _______________________________________________ MediaWiki-l mailing list MediaWiki-l@Wikimedia.org http://mail.wikipedia.org/mailman/listinfo/mediawiki-l
Users aren't *required* to enter an email address in order to create a new MediaWiki account. I suppose we could code a software modification for this, however.
Rob Church
On 12/10/05, Emilien ARNAUD emilien@creatixea.com wrote:
And what about an email verification ? An account is marked to be deleted if not verfied by email after 24h (needs a bot to do that) :)
E.
-----Message d'origine----- De : mediawiki-l-bounces@Wikimedia.org [mailto:mediawiki-l-bounces@Wikimedia.org] De la part de Thompson, Graeme (AELE) Envoyé : mercredi 12 octobre 2005 10:56 À : MediaWiki announcements and site admin list Objet : RE: [Mediawiki-l] Delete passive users ?
Or simply a user configurable limit of being able to only create 1 user per ip per hour.
That would stop excessive user creation into the hundreds from an IP.
-----Original Message----- From: mediawiki-l-bounces@Wikimedia.org [mailto:mediawiki-l-bounces@Wikimedia.org] On Behalf Of GraphoPhile Sent: 12 October 2005 09:24 To: mediawiki-l@Wikimedia.org Subject: [Mediawiki-l] Delete passive users ?
Jani : Does this not provide a fine attack against Mediawikis: make a bot that generates and register users. After some trillions of random users added the wiki is on its knees. GP : From Rob answer I understood that the problem is for links that are created in the system when a user is active. If a bot "just" adds trillions of users I guess he's got no time for creating pages. So these passive users could be erased ??????? The need is of an alarm indicator of "over registration of users".
MediaWiki-l mailing list MediaWiki-l@Wikimedia.org http://mail.wikipedia.org/mailman/listinfo/mediawiki-l
The information contained in, or attached to, this e-mail, may contain confidential information and is intended solely for the use of the individual or entity to whom they are addressed and may be subject to legal privilege. If you have received this e-mail in error you should notify the sender immediately by reply e-mail, delete the message from your system and notify your system manager. Please do not copy it for any purpose, or disclose its contents to any other person. The views or opinions presented in this e-mail are solely those of the author and do not necessarily represent those of the company. The recipient should check this e-mail and any attachments for the presence of viruses. The company accepts no liability for any damage caused, directly or indirectly, by any virus transmitted in this email.
MediaWiki-l mailing list MediaWiki-l@Wikimedia.org http://mail.wikipedia.org/mailman/listinfo/mediawiki-l
MediaWiki-l mailing list MediaWiki-l@Wikimedia.org http://mail.wikipedia.org/mailman/listinfo/mediawiki-l
On 10/12/05, Rob Church robchur@gmail.com wrote:
Users aren't *required* to enter an email address in order to create a new MediaWiki account. I suppose we could code a software modification for this, however.
Isn't there an administrator option to require email authorization? I thought there was..
No; there is, however, an option to require that all email addresses are verified.
Rob Church
On 12/10/05, Sy Ali sy1234@gmail.com wrote:
On 10/12/05, Rob Church robchur@gmail.com wrote:
Users aren't *required* to enter an email address in order to create a new MediaWiki account. I suppose we could code a software modification for this, however.
Isn't there an administrator option to require email authorization? I thought there was.. _______________________________________________ MediaWiki-l mailing list MediaWiki-l@Wikimedia.org http://mail.wikipedia.org/mailman/listinfo/mediawiki-l
In LocalSettings.php, set:
$wgEmailAuthentication = true;
And that will enable it.
Rob Church
On 13/10/05, Karl-Otto Kirst post@karl-kirst.de wrote:
No; there is, however, an option to require that all email addresses are verified.
Where can it be found? - How do I activate this option?
Karl Kirst
MediaWiki-l mailing list MediaWiki-l@Wikimedia.org http://mail.wikipedia.org/mailman/listinfo/mediawiki-l
Hi
On Thu 13-Oct-2005 at 11:07:44AM +0200, Karl-Otto Kirst wrote:
In LocalSettings.php, set:
$wgEmailAuthentication = true;
The above just restrict the email options until the email address has been confirmed...
On Wed 12-Oct-2005 at 09:40:06PM +0100, Rob Church wrote:
Users aren't *required* to enter an email address in order to create a new MediaWiki account. I suppose we could code a software modification for this, however.
I'd like this option -- no editing untill the email address has been confirmed, it would at least prevent some current bots trashing sites...
Chris
Well, http://meta.wikimedia.org/wiki/How_to_become_a_MediaWiki_hacker awaits, then. This is somewhat unwiki, if you ask me.
Rob Church
On 13/10/05, Chris Croome chris@webarchitects.co.uk wrote:
Hi
On Thu 13-Oct-2005 at 11:07:44AM +0200, Karl-Otto Kirst wrote:
In LocalSettings.php, set:
$wgEmailAuthentication = true;
The above just restrict the email options until the email address has been confirmed...
On Wed 12-Oct-2005 at 09:40:06PM +0100, Rob Church wrote:
Users aren't *required* to enter an email address in order to create a new MediaWiki account. I suppose we could code a software modification for this, however.
I'd like this option -- no editing untill the email address has been confirmed, it would at least prevent some current bots trashing sites...
Chris
-- Chris Croome chris@webarchitects.co.uk web design http://www.webarchitects.co.uk/ web content management http://mkdoc.com/ _______________________________________________ MediaWiki-l mailing list MediaWiki-l@Wikimedia.org http://mail.wikipedia.org/mailman/listinfo/mediawiki-l
Users aren't *required* to enter an email address in order to create a new MediaWiki account. I suppose we could code a software modification for this, however.
That would be nice in many cases, for example with students, who like to hide beyond hicknames and than to make some damage.
Karl Kirst
Hi
On Wed 12-Oct-2005 at 02:55:57AM -0600, Thompson, Graeme (AELE) wrote:
Or simply a user configurable limit of being able to only create 1 user per ip per hour.
That would stop excessive user creation into the hundreds from an IP.
Yeah, but the bot that is doing all the damage at the moment attacks from hundereds of different ip addresses so blocking / limiting stuff by ip isn't the answer to stop this attack :-(
Chris
mediawiki-l@lists.wikimedia.org