PDA

View Full Version : Major Spam Attack, 16-17 July


Knockwood
07-17-2006, 06:33 PM
I spent a lot of last night and today trying to clean up the debris from two simultaneous spam attacks.

Last night we got a series of spams where someone would create a new page and populate it with a series of what look like search engine queries... which means you had a lot of sexual stuff, but also things like 'pictures of orcas' and song-lyrics queries. Strange. There were a few linked-to but unwritten pages, but he mainly made pages of the form "MediaWiki talk: (something)", which at least were easy to spot. Anyway, I junked as many of them as I found, but there might be a few lurking around.

Today we got some of that, but also a repeat of the random-numbers spams we've been getting. I know there are still a few of those floating around.

Please check your pages for any of this junk, and delete it if you see it.

This has also prompted a change in our dealing-with-spammers-personally policy. In the past, as you may recall, we would ask you to kill any spammers you meet, preferably messily. With this latest series of spams, that policy has been modified: please injure or confine them, then call us (Shannon and myself), so that we may travel there to watch him die. Alternatively, high-res video of his messy death is encouraged, with a laugh track if possible.

Yr ob'd'ent s'rv'nt (yeah right),
Knockwood

Knockwood
07-20-2006, 05:55 PM
Whoever's putting in the search-engine spam is going whole hog with it... I've just cleaned a whole bunch of pages because of this guy. And it does seem to be search-engine spam; along with the usual porn are things like "10 best movies of 2006" and "events for a baby shower for 50 people".

A quick trip to the MediaWiki site has some potential solutions... for one, there's an extension (I think) that puts in code to do 'Type the characters in the graphic to continue' when the edit includes a link. That may take care of it right off the bat if, as I suspect, it's auto-spam.

There's also the brute-force solution of disabling anonymous edits altogether. I'm not sure about that, since we do get occasional helpful edits from non-members, including the occasional admin of an allied Wiki. On the other hand, it would effectively eliminate spam, since 99.9% of it comes in from non-members.

Comments, thoughts, questions? --TM