[Foundation-l] Re: Autoblocking on all wikis now ?!?!?!

Dori slowpoke at gmail.com
Wed Mar 30 18:28:44 UTC 2005


On Thu, 31 Mar 2005 01:23:56 +1000, Tim Starling
<t.starling at physics.unimelb.edu.au> wrote:
> David Gerard wrote:
> > Has anyone had a chance to look at bug 550? It's specifically so that this
> > sort of block will only hit anon users.
> 
> I've told the list before that the spammers already have software to log
> in to wikis, and the vandals log in whenever it's convenient for them.
> In a previous post, I even gave details of vandalbot attacks by logged
> in users. But I guess you won't believe me that it's useless until you
> see it. I already had an exemption in place for non-newbies, I've
> replaced this with an exemption for all logged-in users.

Tim please don't. We already had a bot page move attacked on sq: (from
[[w:sq:User:Biskota]]). I happened to be online at the time (only two
admins on sq, about 5 regular users), and still it took me and another
contributor a good 20 minutes to clean up all the page moves. If I
hadn't been online the only good way to fix it would have been a db
restore. We were also lucky that it wasn't using a proxy, but it's the
next logical step for an attacker.

Page move and edit throttling for newbie users would also be
tremendously useful (maybe it can be put in 1.5 since the schema is
changing).



More information about the foundation-l mailing list