OSDev.org

The Place to Start for Operating System Developers
It is currently Mon May 06, 2024 5:33 pm

All times are UTC - 6 hours




Post new topic Reply to topic  [ 22 posts ]  Go to page 1, 2  Next
Author Message
 Post subject: OSFaq has been spammed bigtime
PostPosted: Thu Jun 08, 2006 10:56 pm 
Offline
Member
Member
User avatar

Joined: Tue Oct 17, 2006 6:06 pm
Posts: 1437
Location: Vancouver, BC, Canada
Hi,
I just noticed that the OSFaq has fallen victim to a nuclear spam attack. There are many new pages with spam links, as well as edits to existing pages. I don't have the time at the moment to go through all of them and fix things up...

Could whoever administers the FAQ maybe just roll it back to before the spam attack started...?

I @#)$* hate spammers. >:(

_________________
Top three reasons why my OS project died:
  1. Too much overtime at work
  2. Got married
  3. My brain got stuck in an infinite loop while trying to design the memory manager
Don't let this happen to you!


Top
 Profile  
 
 Post subject: Re:OSFaq has been spammed bigtime
PostPosted: Fri Jun 09, 2006 2:51 am 
Offline
Member
Member
User avatar

Joined: Thu Nov 16, 2006 12:01 pm
Posts: 7614
Location: Germany
As I said on osdever.net, I'm at it. (If someone has an up-to-date backup and the ability to install it on the server, feel free to do so, that way we'll lose the spam from the versioning, too.)

_________________
Every good solution is obvious once you've found it.


Top
 Profile  
 
 Post subject: Re:OSFaq has been spammed bigtime
PostPosted: Fri Jun 09, 2006 5:16 am 
Offline
Member
Member
User avatar

Joined: Thu Nov 16, 2006 12:01 pm
Posts: 7614
Location: Germany
Since the spammer has returned mid-effort, the OS FAQ is effectively dead for now until we can a) block the spammer's IPs and b) locate a halfway up-to-date backup of the FAQ.

I'll bring a static XHTML backup online ASAP at http://www.rootdirectory.de/osfaq/ (will take about four hours though before I can get home).

_________________
Every good solution is obvious once you've found it.


Top
 Profile  
 
 Post subject: Re:OSFaq has been spammed bigtime
PostPosted: Fri Jun 09, 2006 5:54 am 
Offline
Member
Member
User avatar

Joined: Fri Oct 22, 2004 11:00 pm
Posts: 1076
everything exceed my companies proxy threshold so I cant do anything at work. all pages break exceeded banned prhase limit and such.

i'm so done with the stupid phpwiki....

_________________
-- Stu --


Top
 Profile  
 
 Post subject: Re:OSFaq has been spammed bigtime
PostPosted: Fri Jun 09, 2006 6:26 am 
Offline
Member
Member
User avatar

Joined: Wed Oct 18, 2006 2:31 am
Posts: 5964
Location: In a galaxy, far, far away
good to know you're on this, DF. The fact it appeared together with the board moves disorganized our fightback ...

note that not only the OSFAQ , but also the Internet as a whole is under massive Spam attack

Here are the address blocks used by the spammers i've gathered so far:
209.8.40.*
206.161.192.*
205.252.23.*
206.161.205.*
209.8.22.*

I guess they should go to the black list ASAP.

_________________
Image May the source be with you.


Top
 Profile  
 
 Post subject: Re:OSFaq has been spammed bigtime
PostPosted: Fri Jun 09, 2006 6:33 am 
Offline
Member
Member
User avatar

Joined: Fri Oct 22, 2004 11:00 pm
Posts: 1076
ok, adding to my .htaccess as I type

_________________
-- Stu --


Top
 Profile  
 
 Post subject: Re:OSFaq has been spammed bigtime
PostPosted: Fri Jun 09, 2006 6:51 am 
Offline
Member
Member
User avatar

Joined: Wed Oct 18, 2006 2:31 am
Posts: 5964
Location: In a galaxy, far, far away
thanks. I removed spam from the "People" pages (well, as many as i found) so that we can at least test the effectiveness of the .htaccess ...

i'll wait a bit before pushing more effort in despamming ... got work to be done if i want money to be paid :P

_________________
Image May the source be with you.


Top
 Profile  
 
 Post subject: Re:OSFaq has been spammed bigtime
PostPosted: Fri Jun 09, 2006 7:13 am 
Offline
Member
Member
User avatar

Joined: Thu Nov 16, 2006 12:01 pm
Posts: 7614
Location: Germany
Honestly no-one with a functional backup of the Wiki? I'd much rather add a dozen edits made after the backup instead of undoing hundreds of spam edits, and I can't picture Pype being too fond of the idea, either.

I could also test my leet Perl skillz and see if I could reverse-engineer the Wiki sources from the XHTML dump...

_________________
Every good solution is obvious once you've found it.


Top
 Profile  
 
 Post subject: Re:OSFaq has been spammed bigtime
PostPosted: Fri Jun 09, 2006 8:17 am 
Offline
Member
Member
User avatar

Joined: Fri Oct 22, 2004 11:00 pm
Posts: 1076
i used to do a DB dump everyday... but I have been so busy with dealing with my mortgage, closing on the new house, and all associated stuff I have not done one in a while... aka long time... :( sorry guys

_________________
-- Stu --


Top
 Profile  
 
 Post subject: Re:OSFaq has been spammed bigtime
PostPosted: Fri Jun 09, 2006 8:45 am 
Offline
Member
Member
User avatar

Joined: Wed Oct 18, 2006 2:31 am
Posts: 5964
Location: In a galaxy, far, far away
well, i've been toying with the wiclicker databases once and tried to retrieve things. I think if i have a recent dump of the database (unspammed), a dump of the current database (even spammed), i could quick-retrieve the pages that can be restored "as is" and leave other page for manual restore.

Maybe i could even find a free day to do it. Don't take me wrong: i'm not too happy with the idea of manually changing all the pages ...

And no, i have no recent dump myself: all my attemps to get a snapshot or a dump of the wiki just resulted in corrupted zip files. All i could ever gather are XHTML dumps.

I remember i changed phpwiki version used in wiclicker (and stopped osdeving for weeks while doing so) for that very purpose ...

Probably we'll have to change the policy and opt for a registration-required framework before people can edit more than one page a day ... problem is that the spammers we're facing now are apparently big (bad) boyz that have pow3rful 3v!l scripts capable of creating hundreds of "fake" accounts on several php-based community software (including e.g. phpnuke boards) ... i'm not even sure we could flood more than 1% of their bandwidth even if were were all synchronizing our resources (and thus probably 'd get fired for resource abuse by our respective managers ::) )

I saw something about "spam-free wiki" where unless you're using a password and have been approved by a moderator, you can't e.g. post URLs in your text ... I'm not sure it'll be easy to migrate the OSFAQ to that system.

_________________
Image May the source be with you.


Top
 Profile  
 
 Post subject: Re:OSFaq has been spammed bigtime
PostPosted: Fri Jun 09, 2006 10:53 am 
Offline
Member
Member
User avatar

Joined: Thu Nov 16, 2006 12:01 pm
Posts: 7614
Location: Germany
A static HTML version of the FAQ (as of 2006-06-01) is online at http://www.rootdirectory.de/osfaq/. Feel free to link to that, I'll holler when my bandwidth allowance bursts. ;)

I'll see what I can do scripting-wise. df, could you mayhaps provide me with a MySQL dump of the Wiki, spam and all (perhaps for download from an URL you send me by PM)? That'd give me another "attack vector" to try.

_________________
Every good solution is obvious once you've found it.


Top
 Profile  
 
 Post subject: Re:OSFaq has been spammed bigtime
PostPosted: Sat Jun 10, 2006 2:11 am 
You should try mediawiki. I think that that keeps a history of page edits, so you can just click on a previous version to revert to that.

-Stephen


Top
  
 
 Post subject: Re:OSFaq has been spammed bigtime
PostPosted: Sat Jun 10, 2006 2:42 am 
Offline
Member
Member
User avatar

Joined: Thu Nov 16, 2006 12:01 pm
Posts: 7614
Location: Germany
PhpWiki does the very same thing. It's just that it isn't fun when you have to revert >100 pages that way.

_________________
Every good solution is obvious once you've found it.


Top
 Profile  
 
 Post subject: Re:OSFaq has been spammed bigtime
PostPosted: Sat Jun 10, 2006 9:58 am 
Offline
Member
Member
User avatar

Joined: Wed Oct 18, 2006 2:31 am
Posts: 5964
Location: In a galaxy, far, far away
well, it seems it has been reverted to the content as of 7 of June ... good news. How has it been ? Have you found a backup dump DF ? or has Solar's 1337 scr1p71n9 sk!llz been invoked ?

_________________
Image May the source be with you.


Top
 Profile  
 
 Post subject: Re:OSFaq has been spammed bigtime
PostPosted: Sun Jun 11, 2006 2:22 am 
Offline
Member
Member
User avatar

Joined: Thu Nov 16, 2006 12:01 pm
Posts: 7614
Location: Germany
Nah, df discovered his 1337 SQL1n9 sk!llz. ;)

_________________
Every good solution is obvious once you've found it.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 22 posts ]  Go to page 1, 2  Next

All times are UTC - 6 hours


Who is online

Users browsing this forum: No registered users and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group