[Mediawiki-l] bot intrusion?

Helmut Hullen Hullen at t-online.de
Fri Sep 12 11:42:00 UTC 2008


Hallo, Platonides,

Du (Platonides) meintest am 28.08.08:

>> I've changed the entry in
>>
>>         http://arktur.de/Wiki/MediaWiki:Titleblacklist
>>
>> to
>>
>>         http <autoconfirmed|noedit|errmsg=Fehlaufruf> # alles
>>
>> but it still doesn't work:
>>
>>         http://arktur.de/Wiki/index.php?title=http://hullen.mydyn.de
>>
>> is still allowed

> However, http://arktur.de/Wiki/index.php?title=Http&action=edit is
> not So you'd need http.*

>> Mediawiki doesn't allow "http://" - sorry.
>> May I put this string into "<nowiki>"?

> Internally, the separator is /, you'd need to escape them:
> http:\/\/.*

That doesn't do the job completely - sorry.

Yesterday I had more than 40 pairs of bot tries like the following:

a-b-c-216-020-xxx.example.com - - [11/Sep/2008:14:30:16 +0200] "GET
/Wiki/index.php?title=Http://204.2.183.2/babycaleb/index.htm%3F HTTP/
1.1" 200 9244 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;
.NET CLR 1.1.4322; .NET CLR 2.0.50727)"
a-b-c-216-020-xxx.example.com - - [11/Sep/2008:14:30:16 +0200] "GET
/Wiki/index.php?title=http://204.2.183.2/babycaleb/index.htm? HTTP/1.1"
301 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR
1.1.4322; .NET CLR 2.0.50727)"

(URLs changed in some places)

Mediawiki accepts the first try and rejects the second.

And I don't know what happens with the accepted request.

I've looked into the file "index.php"; a switch " String 'http://' is  
forbidden" or so may do the desired job, but I don't know where is the  
best place for it.

Viele Gruesse!
Helmut



More information about the MediaWiki-l mailing list