From: | Guillaume Lelarge <guillaume(at)lelarge(dot)info> |
---|---|
To: | Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc> |
Cc: | Andres Freund <andres(at)anarazel(dot)de>, pgsql-www <pgsql-www(at)postgresql(dot)org>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, Bruce Momjian <bruce(at)momjian(dot)us>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Magnus Hagander <magnus(at)hagander(dot)net> |
Subject: | Re: Spam on the wiki |
Date: | 2015-12-16 20:48:58 |
Message-ID: | CAECtzeUN5QHW-P83fw-34yCbn9vMxR4Y79DAX21Gryt3HmcSZw@mail.gmail.com |
Views: | Whole Thread | Raw Message | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-www |
Le 16 déc. 2015 9:24 PM, "Stefan Kaltenbrunner" <stefan(at)kaltenbrunner(dot)cc> a
écrit :
>
> On 12/16/2015 08:24 PM, Stefan Kaltenbrunner wrote:
> > On 12/16/2015 07:53 PM, Tom Lane wrote:
> >> Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc> writes:
> >>>> we are currently working on reverting the entire wiki back to a state
> >>>> before the attack from system backups because it does not seem
sensible
> >>>> to try to revert this in piece meal style.
> >>
> >>> we have now restored a backup from ~2015-12-15 05:00:37 UTC (later
> >>> backups already had spam traces in it) - th wiki is live again, user
> >>> account signup for the entire community account system is still
disabled
> >>> until we have a better plan to deal with this crap.
> >>
> >> "Recent changes" log says there's still at least one active spammer
> >> account.
> >
> > yeah thanks for letting us know - the problem is that it looks like the
> > spammers have pre-created (but not "used" until very recently) a lot of
> > accounts in the community account system over the last few days (if not
> > for much longer) and it is not really obvious which ones are "bad" and
> > which ones are not - we keep working on it :(
>
> I think we have it under control now - we have disabled ~200
> "suspicious" community accounts, restored a backup of the wiki from ~36h
> ago and nuked all the session data from the community auth system and
> the wiki to prevent users from reusing existing sessions.
> That seems to stablized the situation for now but community auth account
> creation is still disabled.
>
> We are currently discussion further actions which will likely involve
> adding additional verification for community auth signup and maybe for
> posting to the wiki. We are also looking into restoring the handful of
> "valid" changes to the wiki between the time of the backup and the time
> we restored it.
>
Thanks Stefan for all the hard work.
From | Date | Subject | |
---|---|---|---|
Next Message | Tom Lane | 2015-12-16 20:58:49 | Re: Spam on the wiki |
Previous Message | Stefan Kaltenbrunner | 2015-12-16 20:24:40 | Re: Spam on the wiki |