ConwayLife.com - A community for Conway's Game of Life and related cellular automata
Home  •  LifeWiki  •  Forums  •  Download Golly

Massive spam attacks on the wiki (and forums?)

For discussion directly related to ConwayLife.com, such as requesting changes to how the forums or wiki function.

Massive spam attacks on the wiki (and forums?)

Postby muzik » July 18th, 2016, 12:47 pm

Some spam accounts are rapidly creating and editing new pages, so much so that it's hard to fit in a speedy deletion template in edgeways without getting an edit conflict and having it being removed by the bots anyway.


Not to mention they're also clogging the living hell out of Special:RecentChanges
Last edited by muzik on July 18th, 2016, 3:44 pm, edited 1 time in total.
2c/n spaceships project

Current priorities: see here
muzik
 
Posts: 2595
Joined: January 28th, 2016, 2:47 pm
Location: Scotland

Re: Massive spam attacks on the wiki

Postby gameoflifeboy » July 18th, 2016, 2:17 pm

Aaaaand now they're on the forums too.

viewtopic.php?f=7&t=2302

viewtopic.php?f=3&t=2301

What a surprise. I thought we had successfully filtered out spambots. (After all, you need to know who discovered the Game of Life to start new pages.)

Maybe these are just especially smart spambots, or maybe they're being directly controlled by a person.
User avatar
gameoflifeboy
 
Posts: 456
Joined: January 15th, 2015, 2:08 am
Location: New Mexico Tech

Re: Massive spam attacks on the wiki

Postby muzik » July 18th, 2016, 3:42 pm

Well this sucks.

If it is a person controlling them, I would like to do things to them I would rather not mention here. However the rate the bots register accounts at is far too fast to be a single person...
2c/n spaceships project

Current priorities: see here
muzik
 
Posts: 2595
Joined: January 28th, 2016, 2:47 pm
Location: Scotland

Re: Massive spam attacks on the wiki (and forums?)

Postby muzik » July 18th, 2016, 4:43 pm

Isn't John Conway the only question/answer there is? We should probably vary it a bit more to slow down the spammers.

Slightly more ambitious approach: block users from creating new pages until both 7 days have passed and they have made 10 edits to pages (and if any of these are spam, the account can be blocked within those 7 days).


Because seriously, this is the most impressive spam attack I have seen in my life.
2c/n spaceships project

Current priorities: see here
muzik
 
Posts: 2595
Joined: January 28th, 2016, 2:47 pm
Location: Scotland

Re: Massive spam attacks on the wiki (and forums?)

Postby Nathaniel » July 18th, 2016, 5:22 pm

For now I've restricted LifeWiki editing access to "trusted" users until we can figure out what the hell happened and a more proper fix. Sorry about this -- this is by far the most ridiculous spam attack this site's ever had.

Edit: I changed the SPAM-prevention questions, but the spammers were not hindered even a little bit -- more new accounts started being made within 5 minutes. Thus the spammer is unfortunately a human (or group of humans), so I will have to leave the trusted-only editing on at least for a little while.
User avatar
Nathaniel
Site Admin
 
Posts: 407
Joined: December 10th, 2008, 3:48 pm
Location: New Brunswick, Canada

Re: Massive spam attacks on the wiki (and forums?)

Postby Apple Bottom » July 18th, 2016, 6:47 pm

Nathaniel wrote:For now I've restricted LifeWiki editing access to "trusted" users until we can figure out what the hell happened and a more proper fix. Sorry about this -- this is by far the most ridiculous spam attack this site's ever had.

Edit: I changed the SPAM-prevention questions, but the spammers were not hindered even a little bit -- more new accounts started being made within 5 minutes. Thus the spammer is unfortunately a human (or group of humans), so I will have to leave the trusted-only editing on at least for a little while.


Yuck. x.x And there's 5000+ spam pages still lingering about.

If you need any help mopping up, I'll be happy to lend a hoof.
Living proof that a little knowledge is a dangerous thing.

Catagolue: Apple Bottom • Life Wiki: Apple Bottom • Twitter: @_AppleBottom_

Proud member of the Pattern Raiders!
User avatar
Apple Bottom
 
Posts: 740
Joined: July 27th, 2015, 2:06 pm

Re: Massive spam attacks on the wiki (and forums?)

Postby codeholic » July 19th, 2016, 4:25 pm

Maybe just restoring all the data from a backup would be a better option? (We do have a backup, don't we?)
Ivan Fomichev
User avatar
codeholic
Moderator
 
Posts: 1138
Joined: September 13th, 2011, 8:23 am
Location: Hamburg, Germany

Re: Massive spam attacks on the wiki (and forums?)

Postby muzik » July 19th, 2016, 4:50 pm

I feel like people should have to post on these forums enough to have their wiki account set to trusted.

Also, Special:NewPages is a fresh picking ground for spam pages to delete.
2c/n spaceships project

Current priorities: see here
muzik
 
Posts: 2595
Joined: January 28th, 2016, 2:47 pm
Location: Scotland

Re: Massive spam attacks on the wiki (and forums?)

Postby Apple Bottom » July 19th, 2016, 6:09 pm

codeholic wrote:Maybe just restoring all the data from a backup would be a better option? (We do have a backup, don't we?)


Oh, no, let's not do that. There's really no reason to lose the (good) edits have been done since then.
Living proof that a little knowledge is a dangerous thing.

Catagolue: Apple Bottom • Life Wiki: Apple Bottom • Twitter: @_AppleBottom_

Proud member of the Pattern Raiders!
User avatar
Apple Bottom
 
Posts: 740
Joined: July 27th, 2015, 2:06 pm

Re: Massive spam attacks on the wiki (and forums?)

Postby muzik » July 20th, 2016, 2:46 pm

Looking at the list of new pages, it seems that all the spam has been pretty much removed (this, unfortunately, has the unwanted side effect of clogging up Recent Changes with deletion log entries).


Now seems like the time to put some better security features into action.
2c/n spaceships project

Current priorities: see here
muzik
 
Posts: 2595
Joined: January 28th, 2016, 2:47 pm
Location: Scotland

Re: Massive spam attacks on the wiki (and forums?)

Postby Apple Bottom » July 20th, 2016, 3:15 pm

muzik wrote:Looking at the list of new pages, it seems that all the spam has been pretty much removed (this, unfortunately, has the unwanted side effect of clogging up Recent Changes with deletion log entries).


There were a couple more spam pages left which I've tagged for speedy deletion now. Most of these were in the various Talk: namespaces, which is why Special:RandomPage wouldn't return them.

I believe I got all of 'em now.

There's still a bunch of recently-registered user accounts that haven't been merged into the "Spam User" account. Minor house-cleaning, but it's probably a good idea to do it anyway.

Now seems like the time to put some better security features into action.


I agree with this. mediawiki.org has some good suggestions; myself I'll particularly recommend the AbuseFilter extension. Used with the right rules it's really powerful, and you only need to add to/update the rules if you get new kinds of spam (or any sort of abuse, really).
Living proof that a little knowledge is a dangerous thing.

Catagolue: Apple Bottom • Life Wiki: Apple Bottom • Twitter: @_AppleBottom_

Proud member of the Pattern Raiders!
User avatar
Apple Bottom
 
Posts: 740
Joined: July 27th, 2015, 2:06 pm

Re: Massive spam attacks on the wiki (and forums?)

Postby muzik » July 20th, 2016, 3:31 pm

My approach would be this:

Keep the trusted-only editing restriction forever.

The user must join these forums first. There would be a thread named something along the lines of "Want to edit the wiki? Post here first" which would highlight a few basic rules and act as a sort of sign-up thread. If a user with 10 or more posts, posts in this thread, then their wiki account will be set to trusted. And since most bots post purely spam, any accounts which are spambots kind of won't be able to get trusted access.


Kind of a harsh approach but it works out.



EDIT: as a side effect of the spam attacks, the speedy deletion pages have been cleared out and the Waterbear and Demonoid infoboxes are fine now!
2c/n spaceships project

Current priorities: see here
muzik
 
Posts: 2595
Joined: January 28th, 2016, 2:47 pm
Location: Scotland

Re: Massive spam attacks on the wiki (and forums?)

Postby M. I. Wright » July 21st, 2016, 8:55 am

I think placing Google's reCAPTCHA (using this extension?) on the account creation and article creation/deletion/edit pages might be sufficient on its own.
M. I. Wright
 
Posts: 313
Joined: June 13th, 2015, 12:04 pm

Re: Massive spam attacks on the wiki (and forums?)

Postby Nathaniel » July 21st, 2016, 9:58 am

Yeah, I really don't want to permanently lock down the wiki to only trusted users. If Wikipedia can manage to let anyone and everyone edit, surely we can too.

I'll look into AbuseFilter. If for nothing else, it can be used to slow down spammers if they do get through our spam-blocking measures (e.g., we can set it so that new accounts are limited in how often they can edit). And I'll look into reCAPTCHA again (I looked at it a while ago but decided against it, but can't remember why anymore). I've also taken some other measures that I won't discuss publicly, since there is at least one real human involved in the SPAM attack.
User avatar
Nathaniel
Site Admin
 
Posts: 407
Joined: December 10th, 2008, 3:48 pm
Location: New Brunswick, Canada

Re: Massive spam attacks on the wiki (and forums?)

Postby muzik » July 22nd, 2016, 10:50 am

How about putting a limit on page title lengths, and anything that exceeds that number blocks the user (if not a trusted account)?
2c/n spaceships project

Current priorities: see here
muzik
 
Posts: 2595
Joined: January 28th, 2016, 2:47 pm
Location: Scotland

Re: Massive spam attacks on the wiki (and forums?)

Postby Scorbie » July 22nd, 2016, 7:37 pm

I think it can be bypassed easily, especially because you already said it here...
Best wishes to you, Scorbie
User avatar
Scorbie
 
Posts: 1327
Joined: December 7th, 2013, 1:05 am

Re: Massive spam attacks on the wiki (and forums?)

Postby drc » July 23rd, 2016, 6:35 pm

Can you trust me on the wiki? My username is drc.
This post was brought to you by the letter D, for dishes that Andrew J. Wade won't do. (Also Daniel, which happens to be me.)
Current rule interest: B2ce3-ir4a5y/S2-c3-y
User avatar
drc
 
Posts: 1665
Joined: December 3rd, 2015, 4:11 pm
Location: creating useless things in OCA

Re: Massive spam attacks on the wiki (and forums?)

Postby Nathaniel » July 23rd, 2016, 6:48 pm

drc wrote:Can you trust me on the wiki? My username is drc.


Done!
User avatar
Nathaniel
Site Admin
 
Posts: 407
Joined: December 10th, 2008, 3:48 pm
Location: New Brunswick, Canada

Re: Massive spam attacks on the wiki (and forums?)

Postby gmc_nxtman » July 24th, 2016, 7:15 pm

Can you add me to the list of trusted users as well? User:Gmc_nxtman
User avatar
gmc_nxtman
 
Posts: 1048
Joined: May 26th, 2015, 7:20 pm

Re: Massive spam attacks on the wiki (and forums?)

Postby Nathaniel » July 25th, 2016, 10:28 am

gmc_nxtman wrote:Can you add me to the list of trusted users as well? User:Gmc_nxtman


Done!
User avatar
Nathaniel
Site Admin
 
Posts: 407
Joined: December 10th, 2008, 3:48 pm
Location: New Brunswick, Canada

Re: Massive spam attacks on the wiki (and forums?)

Postby Rhombic » August 9th, 2016, 9:48 am

May I request access to the "trusted" group in the Wiki? I was about to correct a typo in Octagon 4, and I'm pretty sure that I won't spam in any article (or, for that matter, create irrelevant pages).
http://www.conwaylife.com/wiki/User:Rhombic
User avatar
Rhombic
 
Posts: 763
Joined: June 1st, 2013, 5:41 pm

Re: Massive spam attacks on the wiki (and forums?)

Postby muzik » August 22nd, 2016, 2:23 am

I made a quick edit to LifeWiki:Editor pages just to let any (legit) newcomer know how they can get a trusted account.
2c/n spaceships project

Current priorities: see here
muzik
 
Posts: 2595
Joined: January 28th, 2016, 2:47 pm
Location: Scotland

Re: Massive spam attacks on the wiki (and forums?)

Postby muzik » August 25th, 2016, 3:29 pm

Not neccesarily a spam attack, but some users with 0 posts have links to external websites, which appear to be kind of spammy.
2c/n spaceships project

Current priorities: see here
muzik
 
Posts: 2595
Joined: January 28th, 2016, 2:47 pm
Location: Scotland

Re: Massive spam attacks on the wiki (and forums?)

Postby LegionMammal978 » August 25th, 2016, 10:19 pm

May I (User:LegionMammal978) be added as a trusted user?
User avatar
LegionMammal978
 
Posts: 14
Joined: July 7th, 2016, 9:37 am

Re: Massive spam attacks on the wiki (and forums?)

Postby Kiran » November 9th, 2016, 9:30 am

Why not enforce Scrypt proof of work on new users? This would make it computationally difficult for spammers to make new accounts, and the few they create can be banned quickly. Also, post rate limits can be imposed on new users, to ensure they do not spam too much. Someone who actually wants to join can wait a few minutes for PoW to be solved.
Kiran Linsuain
User avatar
Kiran
 
Posts: 284
Joined: March 4th, 2015, 6:48 pm

Next

Return to Website Discussion

Who is online

Users browsing this forum: No registered users and 1 guest