Cleaning up bogus user accounts

Jon Stahl <[email protected]> Fri, 9 Mar 2012 14:02:39 -0800
Newsgroups gmane.comp.web.zope.plone.website
Message-ID <CAM8toDe4DLFwJ9yqzeY81wRdaDE2zFX3Tpd=GkN2fVWdevqm9w@mail.gmail.com>
Hi all-

Sean Kelly and I have been investigating the state of the plone.org
LDAP database, and we have some recommendations to bounce off of the
larger community.

We have about 58k accounts in the plone.org LDAP system, which
backends authentication for plone.org, dev.plone.org (trac) and is
synced to github.  The vast, vast majority of these accounts (all but
about 2000) are pretty obviously bogus/spam accounts, and most of
these (but not all) were created back in the days when we had a
vulnerability (now closed) related to member portraits, which made it
worthwhile to try to create spam user accounts.

Sean and I believe we can easily nuke all of these accounts with
minimal collateral damage to legit accounts by removing all accounts
that are NOT members of a plone.org LDAP group (e.g. committers,
collective committers, etc.) AND also have not ever created a record
in the Trac database (e.g. a bug report or a comment) AND don't own an
item in http://plone.org/support/sites or
http://plone.org/support/providers.

Can anybody think of a class of legitimate accounts that would be
excluded by the above logic?


---
Jon Stahl
MPA Candidate, Evans School of Public Affairs
University of Washington
http://jstahl.org
206.226.0818

------------------------------------------------------------------------------
Virtualization & Cloud Management Using Capacity Planning
Cloud computing makes use of virtualization - but cloud computing 
also focuses on allowing computing to be delivered as a service.
http://www.accelacomm.com/jaw/sfnl/114/51521223/
_______________________________________________
Plone-website mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/plone-website
The Wiki: http://plone.org/development/current/projects/WebsiteTeam