Mailing List Archive

Vandalism
Hello everybody there.
Yesterday (sunday, december 1st) the french wikipedia was attacked by a
vandal bot (Iala'29899).
Luck for us, at the time the bot attacked there were some sysops logged on
the site and they were able to block the 10 successive IP address it used.
We are worring about new attack and we though about some idea to prevent
vandal to make hell on Wikipedias:

- Display already blocked address in RecentChange in a different way (bold?
italic? different color?) to be able to see quickly witch address was
already blocked and witch are not yet.

- Allow Sysop to have an easy way to block a logged user (in RecentChange if
possible).

- Send warning mail to Sysop (who solicited it) when a user modify some
pages in strange ways (articles size seriously reduced, too many articles
modify in a short laps, ...)

- Provide a tool to repair the dommage. Reverse action of a user/IP from
"date/time 1" to "date/time 2".

Please hearten us ;o)

Aoineko
Re: Vandalism [ In reply to ]
On Mon, 2 Dec 2002, Guillaume Blanchard wrote:
> Hello everybody there.
> Yesterday (sunday, december 1st) the french wikipedia was attacked by a
> vandal bot (Iala'29899).
>
> Luck for us, at the time the bot attacked there were some sysops logged on
> the site and they were able to block the 10 successive IP address it used.
> We are worring about new attack and we though about some idea to prevent
> vandal to make hell on Wikipedias:

The same had hit Meta, Esperanto, and German wikis a few hours earlier
(using randomly titled pages, easily deletable); I cleaned them up and put
a note in the English vandal-watch page (ie, the biggest audience of
active users) asking people to keep an eye open for more activity while I
was asleep.

> - Display already blocked address in RecentChange in a different way (bold?
> italic? different color?) to be able to see quickly witch address was
> already blocked and witch are not yet.

Could be done.

> - Allow Sysop to have an easy way to block a logged user (in RecentChange if
> possible).

Hmm, right now it would be fairly easy to set it up to ban a username, but
they could still log out and continue with the raw IP or a new username,
which you'd have to block separately again...

> - Send warning mail to Sysop (who solicited it) when a user modify some
> pages in strange ways (articles size seriously reduced, too many articles
> modify in a short laps, ...)

Hmm...

> - Provide a tool to repair the dommage. Reverse action of a user/IP from
> "date/time 1" to "date/time 2".

In the works, not done yet.

-- brion vibber (brion @ pobox.com)