[infrastructure-dev] Re: Changes in the OOoWiki backend
Alexandro Colorado <[email protected]> Wed, 4 May 2011 05:55:46 -0500
| Newsgroups | gmane.comp.openoffice.devel.website |
|---|---|
| Message-ID | <[email protected]> |
--00261887757e4f48b204a2711920 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable On Wed, May 4, 2011 at 5:52 AM, Clayton <[email protected]> wrote: > On 05/04/2011 12:43 PM, Alexandro Colorado wrote: > >> >> >> On Wed, May 4, 2011 at 2:01 AM, Clayton <[email protected] >> <mailto:[email protected]>> wrote: >> >> There as been a lot of link spam on the OOoWiki the past few days. >> I'm tired of chasing it, and I imagine the other Admins are >> too.... so I've added some code to the LocalSettings.php file to >> block all edits and page creation to new confirmed accounts. After >> a 4 day "cooling off period" then the new user accounts will have >> edit and page creation rights. Hopefully this is long enough that >> the Spammers get bored and leave... but new users come back. >> >> There are very very few new legitimate users compared to spam >> accounts anyway... and of those new legitimate users maybe one per >> month actually edits a page. The impact of this change on >> legitimate users should be very low. >> >> See: >> >> http://wiki.services.openoffice.org/wiki/Wiki_maintenance/LocalSettings.= php_modifications#Block_new_users_from_editing_or_creating_new_pages_for_4_= days >> for details of the change. >> >> C. >> >> >> Thanks for looking out clayton, should I try to push my users to create >> accounts just in case, or should they do the opposite and wait a few >> days until they create new accounts? >> > > New users can create accounts as usual... it's just that there is a 4 day > period after confirming their account that they cannot edit pages. There = are > no other limitations that I've added... other than the 4 day wait, it's t= he > same as before... so don't tell people not to create accounts if they need > them. > > I'm not sure what else we can do here to combat Spam... we've got > recaptcha, a regex filter for keywords, a bad behavior extension, email > confitmation, another spam trap extension, and still there is loads of SEO > link spam. Lately there has been more spam than legit editing. > > If this is too disruptive, I can of course remove the restrictions or > reduce the wait time. > > I'm also open to any other ideas if the community doesn't like this > solution :-) > > C. > > I wonder if we are being targeted or maybe is a big vulnerability found on mediawiki that is now being exploited internetwide by spammers. Have you check with the security alerts of mediawiki? --=20 *Alexandro Colorado* *OpenOffice.org* Espa=C3=B1ol http://es.openoffice.org --=20 ----------------------------------------------------------------- To unsubscribe send email to [email protected] For additional commands send email to [email protected] with Subject: help --00261887757e4f48b204a2711920 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <br><br><div class=3D"gmail_quote">On Wed, May 4, 2011 at 5:52 AM, Clayton = <span dir=3D"ltr"><<a href=3D"mailto:[email protected]">ccornell@o= penoffice.org</a>></span> wrote:<br><blockquote class=3D"gmail_quote" st= yle=3D"margin: 0pt 0pt 0pt 0.8ex; border-left: 1px solid rgb(204, 204, 204)= ; padding-left: 1ex;"> <div class=3D"im">On 05/04/2011 12:43 PM, Alexandro Colorado wrote:<br> </div><blockquote class=3D"gmail_quote" style=3D"margin: 0pt 0pt 0pt 0.8ex;= border-left: 1px solid rgb(204, 204, 204); padding-left: 1ex;"><div class= =3D"im"> <br> <br> On Wed, May 4, 2011 at 2:01 AM, Clayton <<a href=3D"mailto:ccornell@open= office.org" target=3D"_blank">[email protected]</a><br></div><div cla= ss=3D"im"> <mailto:<a href=3D"mailto:[email protected]" target=3D"_blank">cco= [email protected]</a>>> wrote:<br> <br> =C2=A0 =C2=A0There as been a lot of link spam on the OOoWiki the past few = days.<br> =C2=A0 =C2=A0 =C2=A0I'm tired of chasing it, and I imagine the other A= dmins are<br> =C2=A0 =C2=A0too.... so I've added some code to the LocalSettings.php = file to<br> =C2=A0 =C2=A0block all edits and page creation to new confirmed accounts. = =C2=A0After<br> =C2=A0 =C2=A0a 4 day "cooling off period" then the new user acco= unts will have<br> =C2=A0 =C2=A0edit and page creation rights. =C2=A0Hopefully this is long e= nough that<br> =C2=A0 =C2=A0the Spammers get bored and leave... but new users come back.<= br> <br> =C2=A0 =C2=A0There are very very few new legitimate users compared to spam= <br> =C2=A0 =C2=A0accounts anyway... and of those new legitimate users maybe on= e per<br> =C2=A0 =C2=A0month actually edits a page. =C2=A0The impact of this change = on<br> =C2=A0 =C2=A0legitimate users should be very low.<br> <br> =C2=A0 =C2=A0See:<br> =C2=A0 =C2=A0<a href=3D"http://wiki.services.openoffice.org/wiki/Wiki_main= tenance/LocalSettings.php_modifications#Block_new_users_from_editing_or_cre= ating_new_pages_for_4_days" target=3D"_blank">http://wiki.services.openoffi= ce.org/wiki/Wiki_maintenance/LocalSettings.php_modifications#Block_new_user= s_from_editing_or_creating_new_pages_for_4_days</a><br> =C2=A0 =C2=A0for details of the change.<br> <br> =C2=A0 =C2=A0C.<br> <br> <br> Thanks for looking out clayton, should I try to push my users to create<br> accounts just in case, or should they do the opposite and wait a few<br> days until they create new accounts?<br> </div></blockquote> <br> New users can create accounts as usual... it's just that there is a 4 d= ay period after confirming their account that they cannot edit pages. There= are no other limitations that I've added... other than the 4 day wait,= it's the same as before... so don't tell people not to create acco= unts if they need them.<br> <br> I'm not sure what else we can do here to combat Spam... we've got r= ecaptcha, a regex filter for keywords, a bad behavior extension, email conf= itmation, another spam trap extension, and still there is loads of SEO link= spam. =C2=A0Lately there has been more spam than legit editing.<br> <br> If this is too disruptive, I can of course remove the restrictions or reduc= e the wait time.<br> <br> I'm also open to any other ideas if the community doesn't like this= solution :-)<br><font color=3D"#888888"> <br> C.</font><div><div></div><br></div></blockquote><div><br>I wonder if we are= being targeted or maybe is a big vulnerability found on mediawiki that is = now being exploited internetwide by spammers. Have you check with the secur= ity alerts of mediawiki?<br> =C2=A0</div></div>-- <br><b>Alexandro Colorado</b><br><b><span style=3D"col= or: rgb(0, 0, 153);">Open</span><span style=3D"color: rgb(0, 0, 0);">Office= .org</span></b> Espa=C3=B1ol<br><a href=3D"http://es.openoffice.org" target= =3D"_blank">http://es.openoffice.org</a><br> <br> --00261887757e4f48b204a2711920--