SPAM attacks on the Wiki

Status
Not open for further replies.

ka3jjz

Wiki Admin Emeritus
Joined
Jul 22, 2002
Messages
25,362
Location
Bowie, Md.
Folks we've been the target of some rather determined spam attacks on our wiki. For the most part - tho not always - it seems that some idiot is getting their jollies writing a spambot that puts numerous junk links on our 'talk' pages

This is the unfortunate price of having a wide open system, as the Wiki is. I've been reverting (most times just wiping out) the junk on these pages and banning where I can; however I am going to be away this weekend on family business and won't be able to access a PC until late on Sunday, if then.

I'd appreciate it if a few of you would keep an eye on the Wiki (you can see the changes easily - simply click on 'recent changes' in the quicklinks on the left) and wipe any changes that appear to be junk. The IDs are immediately obvious - they tend to be a mix of random letters and numbers. I see that mwJones has been doing exactly this (Thanks!) but with just over 500 articles, one person can't do it alone.

I've written Lindsay to try to get a 2nd admin to help share the load but I think he's still on his well-deserved vacation. Until the 3.0 changes get installed, we will all need to be a bit vigilant for such actions.

73s and thanks....Mike
 

loumaag

Silent Key - Aug 2014
Joined
Oct 20, 2002
Messages
12,935
Location
Katy, TX
Mike, where can we assemble a list of people you need to ban?
One I just reversed was OfjV00 reference the APCO-16 page.

I will just keep a list here (below) in addition to the one above.

Additional spambots needed to be banned:
Code:
Jwsld8 -> damage to MPT-1327 page.
EprZvw -> damage to IC_PCR2500/IC-R2500 page.
BjwRef -> new spam page Talk:DRD DXG POI (should probably just delete this)
 
Last edited:

KC1UA

Scan New England Janitor/Maintenance
Database Admin
Joined
Oct 27, 2002
Messages
2,051
Location
Marstons Mills, Cape Cod, Massachusetts
There's really no way to combat this other than to implement image verification, which is available as an option in a later version of the Wiki, as I recall. I couldn't do it with mine as the mySQL version at my webhost was not high enough to upgrade to the latest version. I was getting killed as well and ultimately wound up shutting off automated registrations. Now if someone wants to edit, they have to e-mail me. That would be a pain in the backside here, but it helped in my case where I have a much smaller Wiki with much fewer contributors. It did eliminate the problem and I usually get a few requests a day from users that want to register.

I'll try to look over the weekend and help in some small way if I can.
 

mwjones

Member
Premium Subscriber
Joined
Apr 9, 2003
Messages
594
Location
Van Alstyne, TX
I'll keep up checking as well. I know I thrashed several out last night (and am on my way to the wiki to check right after I submit this)
 

ka3jjz

Wiki Admin Emeritus
Joined
Jul 22, 2002
Messages
25,362
Location
Bowie, Md.
I appreciate this, all of you. I will check the wiki in a few moments here and see what damage needs to be undone. 73s Mike
 

loumaag

Silent Key - Aug 2014
Joined
Oct 20, 2002
Messages
12,935
Location
Katy, TX
Just noticed that Paul got rid of some info but you need to ban MvgQd3.
 

KC1UA

Scan New England Janitor/Maintenance
Database Admin
Joined
Oct 27, 2002
Messages
2,051
Location
Marstons Mills, Cape Cod, Massachusetts
Unfortunately, banning any of them is not going to make a difference. They are just randomly generated by bots, which then place links to their websites on various pages, either via hidden text or in a more destructive manner that wipes the existing page. Fortunately a rollback can be done.

They will continue to attack in this manner until either the image verification I mentioned is utilized for the registration procedure, or automated registrations are shut off in their entirety. The easiest thing to do is to not waste time with banning, fix the pages, and then have an authorized person use MySQL admin to go into the database itself and do a global delete of the offenders.
 

loumaag

Silent Key - Aug 2014
Joined
Oct 20, 2002
Messages
12,935
Location
Katy, TX
scancapecod said:
...They will continue to attack in this manner until either the image verification I mentioned is utilized for the registration procedure, or automated registrations are shut off in their entirety. The easiest thing to do is to not waste time with banning, fix the pages, and then have an authorized person use MySQL admin to go into the database itself and do a global delete of the offenders.
The image verification idea is a good one, perhaps Lindsay can look into it on his return.
 

hoser147

Member
Joined
Dec 17, 2005
Messages
4,449
Location
Grand Lake St. Marys Ohio
Unfortunately if the is a will theres a way, Not to get off topic there has been a number of newbies wanting to come right on and sell items here. Maybe they should have to be around awhile before they are permitted to do this. Just to Protect Members. Hoser147
 

blantonl

Founder and CEO
Staff member
Super Moderator
Joined
Dec 9, 2000
Messages
11,098
Location
San Antonio, Whitefish, New Orleans
We are going to address this with a custom registration component integrated with the rest of the site - which will render the bots useless.

Bots are written to attack and exploit common registration components, that's why you don't see bots attacking the forums or the site because we use a custom registration component. This will be extended to the wiki for the 3.0 release.
 

loumaag

Silent Key - Aug 2014
Joined
Oct 20, 2002
Messages
12,935
Location
Katy, TX
Okay, to store the Bot ID's and damage done, I have created a page on the Wiki. When this problem goes away, this page can be gotten rid of, but in the meantime saving the Bot ID Page link will save us having to communicate via the forum.
 

bezking

Member
Joined
Aug 5, 2006
Messages
2,656
Location
On the Road
loumaag said:
Okay, to store the Bot ID's and damage done, I have created a page on the Wiki. When this problem goes away, this page can be gotten rid of, but in the meantime saving the Bot ID Page link will save us having to communicate via the forum.

Adding bots.....:(
 
Last edited:

ka3jjz

Wiki Admin Emeritus
Joined
Jul 22, 2002
Messages
25,362
Location
Bowie, Md.
Folks I just got back from NJ about 4 hours ago, and am still a bit bleary eyed and road burned. I will look at the changes log and bot id page during lunch and hopefully catch up on all the bots and damage that hasn't yet been reverted.

Thanks for your patience - 73s Mike
 

ka3jjz

Wiki Admin Emeritus
Joined
Jul 22, 2002
Messages
25,362
Location
Bowie, Md.
I just blocked 3 pages plus of Bot IDs - whoever has created the Bot ID page, please reset for the next list of Bots. Took me my whole lunch hour - I shudder what it would have taken on my dialup.
Whoever is maintaining that article, please delete the IDs and scan for any other Bot IDs that have happened since the last one was entered.
73s and thanks to everyone for their help - it's much appreciated Mike
 
Status
Not open for further replies.
Top