• Welcome to NIWA Community Forums.
 

DKWiki is under serious attack

Started by HavocReaper48, March 20, 2011, 03:33:19 PM

Previous topic - Next topic

HavocReaper48

http://www.donkeykongwiki.com/Special:RecentChanges

Has this happened to anyone else? And can anyone assist the reverts?

Member#36

Have you added the extension to where a user must answer a question before saving the edit?

porplemontage

Quote from: Member#36 on March 20, 2011, 03:34:30 PM
Have you added the extension to where a user must answer a question before saving the edit?
Yes, but it doesn't stop human vandals.
Steve

HavocReaper48

Quote from: porplemontage on March 20, 2011, 03:38:46 PM
Quote from: Member#36 on March 20, 2011, 03:34:30 PM
Have you added the extension to where a user must answer a question before saving the edit?
Yes, but it doesn't stop human vandals.
Yeah, DKWiki has had spammer accounts before but this is the first major flesh & blood vandal wiki attack in DKWiki history since the April Fools Incident. And that was on Wikia.

UltimateSephiroth

#4
For now, what would probably help you the most is to restrict editing temporarily to staff only.

Deriving from MediaWiki manual, this would probably look as follows (added into LocalSettings.php), though I'm not especially familiar with administrative MediaWiki using, so you might want to check it yourself:
$wgGroupPermissions['*']['edit'] = false;
$wgGroupPermissions['user']['edit'] = false;
$wgGroupPermissions['sysop']['edit'] = true;


Also holy crap I haven't been here for ages. :F

HavocReaper48

More specifically, where do I add that coding?

Like, "MediaWiki:__"?

UltimateSephiroth

Quote from: HavocReaper48 on March 20, 2011, 07:22:52 PM
More specifically, where do I add that coding?

Like, "MediaWiki:__"?
If you don't have access to the site FTP (or physical access to the server), you can't do it. That method would involve editing a configuration file, not a database entry like a wiki page (or metapage).

Jake

If you have permission, you can also use Special:LockDB to shut down editing until your server admin can add that code. :)

Greenpickle

Maybe there's a way to restrict making large changes, as all of those edits seem to be, to autoconfirmed users (users with 4-day-old accounts according to MediaWiki; according to porple, they need 10 edits too, though this might just be something he's configured)?  That would block most of the edits, but I have no idea if it's possible...  If you can't, a good start would at least be only allowing autoconfirmed users to create pages, maybe.

Miles of SmashWiki

Same guy hit SmashWiki, as you may have seen; just revert, block and be sure to restrict account creation on the block form.  Is there something more major that would need to be done?


Srsbsns is always lurking (?_?)

Xizor

Yeah, really the only way to stop a vandal is to restrict their access and/or just clean up after them.

Others will have more sufficient technical advice.



Bureaucrat of

Member#36

It seems that the issue has been taken care of.

Omega Tyrant

Quote from: Miles of SmashWiki on March 21, 2011, 04:34:52 PM
Same guy hit SmashWiki, as you may have seen; just revert, block and be sure to restrict account creation on the block form.  Is there something more major that would need to be done?

The vandal had a changing IP, so that was ineffective. Regardless, he is gone for now.

tacopill

Quote from: Omega Tyrant on March 22, 2011, 11:23:17 PM
Quote from: Miles of SmashWiki on March 21, 2011, 04:34:52 PM
Same guy hit SmashWiki, as you may have seen; just revert, block and be sure to restrict account creation on the block form.  Is there something more major that would need to be done?

The vandal had a changing IP, so that was ineffective. Regardless, he is gone for now.

good to hear he left.....  my guess is he got bored.