Re: Spam on the wiki

Lists: pgsql-www
From: Guillaume Lelarge <guillaume(at)lelarge(dot)info>
To: pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Spam on the wiki
Date: 2015-12-16 16:32:19
Message-ID: CAECtzeUBkTXdbyWyy+B9yjr9ge9sf48fB0_vsD-tY=RXeQ81BA@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: Postg토토 사이트SQL : Postg토토 사이트SQL 메일 링리스트 : 2015-12-16 이후 PGSQL WWW 16:32

Hi,

There's something wrong over here:
https://wiki.postgresql.org/wiki/Talk:What's_new_in_PostgreSQL_9.1/fr

And to many more pages. See:
https://wiki.postgresql.org/index.php?title=Special%3ALog&type=&user=Singhuma893

Not sure what's the best way to deal with this, but wanted you guys to know
about it.

--
Guillaume.
http://blog.guillaume.lelarge.info
http://www.dalibo.com


From: Bruce Momjian <bruce(at)momjian(dot)us>
To: Guillaume Lelarge <guillaume(at)lelarge(dot)info>
Cc: pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 17:02:04
Message-ID: 20151216170204.GA2577@momjian.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Wed, Dec 16, 2015 at 05:32:19PM +0100, Guillaume Lelarge wrote:
> Hi,
>
> There's something wrong over here: https://wiki.postgresql.org/wiki/
> Talk:What's_new_in_PostgreSQL_9.1/fr
>
> And to many more pages. See: https://wiki.postgresql.org/index.php?title=
> Special%3ALog&type=&user=Singhuma893
>
> Not sure what's the best way to deal with this, but wanted you guys to know
> about it.

Yes, I am trying to fix it but the spam users are creating new pages
faster than I can fix it. I am concerned we are going to need to revert
the entire wiki to an earlier state.

I see problem users Johnthe and Sanjaypatel but the fixes are geting
re-spammed so quickly I am afraid it is some automated attack that will
be difficult to clean up. The other problem is that they are _moving_
pages, meaning we have to move them back as well as undo the edits.

I am going to give up trying to undo this until we can get a better
handle on a process of cleanup.

--
Bruce Momjian <bruce(at)momjian(dot)us> http://momjian.us
EnterpriseDB http://enterprisedb.com

+ As you are, so once was I. As I am, so you will be. +
+ Roman grave inscription +


From: Guillaume Lelarge <guillaume(at)lelarge(dot)info>
To: Bruce Momjian <bruce(at)momjian(dot)us>
Cc: pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 17:06:52
Message-ID: CAECtzeU=tzWms2pyaWcQHtZQtruM1GgjUo6NLxS=AW-qwnqW_A@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

2015-12-16 18:02 GMT+01:00 Bruce Momjian <bruce(at)momjian(dot)us>:

> On Wed, Dec 16, 2015 at 05:32:19PM +0100, Guillaume Lelarge wrote:
> > Hi,
> >
> > There's something wrong over here: https://wiki.postgresql.org/wiki/
> > Talk:What's_new_in_PostgreSQL_9.1/fr
> >
> > And to many more pages. See:
> https://wiki.postgresql.org/index.php?title=
> > Special%3ALog&type=&user=Singhuma893
> >
> > Not sure what's the best way to deal with this, but wanted you guys to
> know
> > about it.
>
> Yes, I am trying to fix it but the spam users are creating new pages
> faster than I can fix it. I am concerned we are going to need to revert
> the entire wiki to an earlier state.
>
> I see problem users Johnthe and Sanjaypatel but the fixes are geting
> re-spammed so quickly I am afraid it is some automated attack that will
> be difficult to clean up. The other problem is that they are _moving_
> pages, meaning we have to move them back as well as undo the edits.
>
> I am going to give up trying to undo this until we can get a better
> handle on a process of cleanup.
>
>
Maybe there's a way to pu the wiki on a read-only mode for everyone except
some of us. That would help stopping them while we fix it. But I don't know
if such a mode exists. +

--
Guillaume.
http://blog.guillaume.lelarge.info
http://www.dalibo.com


From: Bruce Momjian <bruce(at)momjian(dot)us>
To: Guillaume Lelarge <guillaume(at)lelarge(dot)info>
Cc: pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 17:08:17
Message-ID: 20151216170817.GB2577@momjian.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Wed, Dec 16, 2015 at 06:06:52PM +0100, Guillaume Lelarge wrote:
> I am going to give up trying to undo this until we can get a better
> handle on a process of cleanup.
>
>
>
> Maybe there's a way to pu the wiki on a read-only mode for everyone except some
> of us. That would help stopping them while we fix it. But I don't know if such
> a mode exists.                             +

Agreed. I cleaned up the page
https://wiki.postgresql.org/wiki/Parallel_Query_Execution and renamed it
back to its original name, but within two minutes it was spammed again.

--
Bruce Momjian <bruce(at)momjian(dot)us> http://momjian.us
EnterpriseDB http://enterprisedb.com

+ As you are, so once was I. As I am, so you will be. +
+ Roman grave inscription +


From: Kevin Grittner <kgrittn(at)gmail(dot)com>
To: Bruce Momjian <bruce(at)momjian(dot)us>
Cc: Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 17:09:38
Message-ID: CACjxUsMTpA8FJJf_MdV+8YZ2hTPDbT3wWGAUc64X0_HBcjCvQQ@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

Looking at the Wiki's change log, it appears to be logging about 10
changes per second.

Kevin Grittner

On Wed, Dec 16, 2015 at 11:08 AM, Bruce Momjian <bruce(at)momjian(dot)us> wrote:
> On Wed, Dec 16, 2015 at 06:06:52PM +0100, Guillaume Lelarge wrote:
>> I am going to give up trying to undo this until we can get a better
>> handle on a process of cleanup.
>>
>>
>>
>> Maybe there's a way to pu the wiki on a read-only mode for everyone except some
>> of us. That would help stopping them while we fix it. But I don't know if such
>> a mode exists. +
>
> Agreed. I cleaned up the page
> https://wiki.postgresql.org/wiki/Parallel_Query_Execution and renamed it
> back to its original name, but within two minutes it was spammed again.
>
> --
> Bruce Momjian <bruce(at)momjian(dot)us> http://momjian.us
> EnterpriseDB http://enterprisedb.com
>
> + As you are, so once was I. As I am, so you will be. +
> + Roman grave inscription +
>
>
> --
> Sent via pgsql-www mailing list (pgsql-www(at)postgresql(dot)org)
> To make changes to your subscription:
> http://www.postgresql.org/mailpref/pgsql-www

--
Kevin Grittner
EDB: http://www.enterprisedb.com
The Enterprise PostgreSQL Company


From: Bruce Momjian <bruce(at)momjian(dot)us>
To: Kevin Grittner <kgrittn(at)gmail(dot)com>
Cc: Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 17:11:12
Message-ID: 20151216171112.GD2577@momjian.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Wed, Dec 16, 2015 at 11:09:38AM -0600, Kevin Grittner wrote:
> Looking at the Wiki's change log, it appears to be logging about 10
> changes per second.

Yikes!

--
Bruce Momjian <bruce(at)momjian(dot)us> http://momjian.us
EnterpriseDB http://enterprisedb.com

+ As you are, so once was I. As I am, so you will be. +
+ Roman grave inscription +


From: Kevin Grittner <kgrittn(at)gmail(dot)com>
To: Bruce Momjian <bruce(at)momjian(dot)us>
Cc: Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 17:11:28
Message-ID: CACjxUsO1xMPb0EaqQmTG2J2Gdu2uzN6YnHBJ6Gm8JF1kyH71Sw@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Wed, Dec 16, 2015 at 11:09 AM, Kevin Grittner <kgrittn(at)gmail(dot)com> wrote:
> Looking at the Wiki's change log, it appears to be logging about 10
> changes per second.

Sorry, 10 changes per minute.

Still...

Kevin Grittner


From: Guillaume Lelarge <guillaume(at)lelarge(dot)info>
To: Kevin Grittner <kgrittn(at)gmail(dot)com>
Cc: Bruce Momjian <bruce(at)momjian(dot)us>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 17:12:23
Message-ID: CAECtzeVutp4arB+uJK83Dj0Gg_Ob8_uxUy7qozsBSGS8P9hv2Q@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

2015-12-16 18:11 GMT+01:00 Kevin Grittner <kgrittn(at)gmail(dot)com>:

> On Wed, Dec 16, 2015 at 11:09 AM, Kevin Grittner <kgrittn(at)gmail(dot)com>
> wrote:
> > Looking at the Wiki's change log, it appears to be logging about 10
> > changes per second.
>
> Sorry, 10 changes per minute.
>
> Still...
>
>
Still worse than our fix time :-/

--
Guillaume.
http://blog.guillaume.lelarge.info
http://www.dalibo.com


From: Dave Page <dpage(at)pgadmin(dot)org>
To: Bruce Momjian <bruce(at)momjian(dot)us>
Cc: Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 17:16:46
Message-ID: CA+OCxoyASu_=cijoSGvPODrbtmSTExoPskHFPVMaQPuhz+KVdw@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Wed, Dec 16, 2015 at 5:02 PM, Bruce Momjian <bruce(at)momjian(dot)us> wrote:
> On Wed, Dec 16, 2015 at 05:32:19PM +0100, Guillaume Lelarge wrote:
>> Hi,
>>
>> There's something wrong over here: https://wiki.postgresql.org/wiki/
>> Talk:What's_new_in_PostgreSQL_9.1/fr
>>
>> And to many more pages. See: https://wiki.postgresql.org/index.php?title=
>> Special%3ALog&type=&user=Singhuma893
>>
>> Not sure what's the best way to deal with this, but wanted you guys to know
>> about it.
>
> Yes, I am trying to fix it but the spam users are creating new pages
> faster than I can fix it. I am concerned we are going to need to revert
> the entire wiki to an earlier state.
>
> I see problem users Johnthe and Sanjaypatel but the fixes are geting
> re-spammed so quickly I am afraid it is some automated attack that will
> be difficult to clean up. The other problem is that they are _moving_
> pages, meaning we have to move them back as well as undo the edits.
>
> I am going to give up trying to undo this until we can get a better
> handle on a process of cleanup.

I've blocked those two users, and it looks like Alvarro has done a few more.

--
Dave Page
Blog: http://pgsnake.blogspot.com
Twitter: @pgsnake

EnterpriseDB UK: http://www.enterprisedb.com
The Enterprise PostgreSQL Company


From: Kevin Grittner <kgrittn(at)gmail(dot)com>
To: Dave Page <dpage(at)pgadmin(dot)org>
Cc: Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 17:19:31
Message-ID: CACjxUsNm1t0FWeVDnb1mJrr5=K2nBiTynAWozmbn_1SarZ2LHA@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Wed, Dec 16, 2015 at 11:16 AM, Dave Page <dpage(at)pgadmin(dot)org> wrote:

> I've blocked those two users, and it looks like Alvarro has done
> a few more.

There seem to be a lot of user IDs involved. Do we know whether
there are new user registrations happening, or were all these set
up before the attack?

--
Kevin Grittner
EDB: http://www.enterprisedb.com
The Enterprise PostgreSQL Company


From: Magnus Hagander <magnus(at)hagander(dot)net>
To: Kevin Grittner <kgrittn(at)gmail(dot)com>
Cc: Dave Page <dpage(at)pgadmin(dot)org>, Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 17:21:14
Message-ID: CABUevEx02gro===aOSStUUmzkiWPX75mPYoL_zChUw_Y6d5cPw@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: Postg토토 사이트 추천SQL : Postg토토 사이트 추천SQL 메일 링리스트 : 2015-12-16 이후 PGSQL www 17:21

On Wed, Dec 16, 2015 at 6:19 PM, Kevin Grittner <kgrittn(at)gmail(dot)com> wrote:

> On Wed, Dec 16, 2015 at 11:16 AM, Dave Page <dpage(at)pgadmin(dot)org> wrote:
>
> > I've blocked those two users, and it looks like Alvarro has done
> > a few more.
>
> There seem to be a lot of user IDs involved. Do we know whether
> there are new user registrations happening, or were all these set
> up before the attack?
>
> --
> Kevin Grittner
> EDB: http://www.enterprisedb.com
> The Enterprise PostgreSQL Company
>
>
> --
> Sent via pgsql-www mailing list (pgsql-www(at)postgresql(dot)org)
> To make changes to your subscription:
> http://www.postgresql.org/mailpref/pgsql-www
>

--
Magnus Hagander
Me: http://www.hagander.net/
Work: http://www.redpill-linpro.com/


From: Magnus Hagander <magnus(at)hagander(dot)net>
To: Kevin Grittner <kgrittn(at)gmail(dot)com>
Cc: Dave Page <dpage(at)pgadmin(dot)org>, Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 17:21:47
Message-ID: CABUevEyFvPPLZciJq+bihsW=-K2VmHnw4jc0hO6DZeOaOXD7hQ@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: Postg토토 사이트 추천SQL : Postg토토 사이트 추천SQL 메일 링리스트 : 2015-12-16 이후 PGSQL www 17:21

On Wed, Dec 16, 2015 at 6:19 PM, Kevin Grittner <kgrittn(at)gmail(dot)com> wrote:

> On Wed, Dec 16, 2015 at 11:16 AM, Dave Page <dpage(at)pgadmin(dot)org> wrote:
>
> > I've blocked those two users, and it looks like Alvarro has done
> > a few more.
>
> There seem to be a lot of user IDs involved. Do we know whether
> there are new user registrations happening, or were all these set
> up before the attack?
>

There are new user registrations happening. Not sure if those are the ones
used, but there definitely are.

Either they've found a way to script-generate gmail addresses, or they have
found a way to break the django hashes.

--
Magnus Hagander
Me: http://www.hagander.net/
Work: http://www.redpill-linpro.com/


From: Andres Freund <andres(at)anarazel(dot)de>
To: Magnus Hagander <magnus(at)hagander(dot)net>
Cc: Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 17:22:55
Message-ID: 20151216172255.GG23112@awork2.anarazel.de
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On 2015-12-16 18:21:47 +0100, Magnus Hagander wrote:
> Either they've found a way to script-generate gmail addresses, or they have
> found a way to break the django hashes.

Or they just hired somebody to do that kind of thing manually. There's
sites for that...


From: "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>
To: Andres Freund <andres(at)anarazel(dot)de>, Magnus Hagander <magnus(at)hagander(dot)net>
Cc: Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 17:27:30
Message-ID: 56719F02.40208@commandprompt.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On 12/16/2015 09:22 AM, Andres Freund wrote:
> On 2015-12-16 18:21:47 +0100, Magnus Hagander wrote:
>> Either they've found a way to script-generate gmail addresses, or they have
>> found a way to break the django hashes.
>
> Or they just hired somebody to do that kind of thing manually. There's
> sites for that...
>
>

In the interim, let's just disable edits.

--
Command Prompt, Inc. - http://www.commandprompt.com/ 503-667-4564
PostgreSQL Centered full stack support, consulting and development.
Announcing "I'm offended" is basically telling the world you can't
control your own emotions, so everyone else should do it for you.


From: Magnus Hagander <magnus(at)hagander(dot)net>
To: "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>
Cc: Andres Freund <andres(at)anarazel(dot)de>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 17:28:18
Message-ID: CABUevExrxpB9rk1JhpuR5cmEuYSH6Z4oa4iho989rN98dOi9jg@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Wed, Dec 16, 2015 at 6:27 PM, Joshua D. Drake <jd(at)commandprompt(dot)com>
wrote:

> On 12/16/2015 09:22 AM, Andres Freund wrote:
>
>> On 2015-12-16 18:21:47 +0100, Magnus Hagander wrote:
>>
>>> Either they've found a way to script-generate gmail addresses, or they
>>> have
>>> found a way to break the django hashes.
>>>
>>
>> Or they just hired somebody to do that kind of thing manually. There's
>> sites for that...
>>
>>
>>
> In the interim, let's just disable edits.

New account signups have been temporarily disabled at least. But yes, they
still have all those accounts against the wiki as well.

--
Magnus Hagander
Me: http://www.hagander.net/
Work: http://www.redpill-linpro.com/


From: Bruce Momjian <bruce(at)momjian(dot)us>
To: Magnus Hagander <magnus(at)hagander(dot)net>
Cc: "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Andres Freund <andres(at)anarazel(dot)de>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 17:29:32
Message-ID: 20151216172932.GE2577@momjian.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Wed, Dec 16, 2015 at 06:28:18PM +0100, Magnus Hagander wrote:
> On Wed, Dec 16, 2015 at 6:27 PM, Joshua D. Drake <jd(at)commandprompt(dot)com> wrote:
>
> On 12/16/2015 09:22 AM, Andres Freund wrote:
>
> On 2015-12-16 18:21:47 +0100, Magnus Hagander wrote:
>
> Either they've found a way to script-generate gmail addresses, or
> they have
> found a way to break the django hashes.
>
>
> Or they just hired somebody to do that kind of thing manually. There's
> sites for that...
>
>
>
>
> In the interim, let's just disable edits.
>
>
> New account signups have been temporarily disabled at least. But yes, they
> still have all those accounts against the wiki as well. 

What is the plan for undoing the spam edits?

--
Bruce Momjian <bruce(at)momjian(dot)us> http://momjian.us
EnterpriseDB http://enterprisedb.com

+ As you are, so once was I. As I am, so you will be. +
+ Roman grave inscription +


From: Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc>
To: Bruce Momjian <bruce(at)momjian(dot)us>
Cc: Magnus Hagander <magnus(at)hagander(dot)net>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Andres Freund <andres(at)anarazel(dot)de>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 18:12:18
Message-ID: 5671A982.7040207@kaltenbrunner.cc
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On 12/16/2015 06:29 PM, Bruce Momjian wrote:
> On Wed, Dec 16, 2015 at 06:28:18PM +0100, Magnus Hagander wrote:
>> On Wed, Dec 16, 2015 at 6:27 PM, Joshua D. Drake <jd(at)commandprompt(dot)com> wrote:
>>
>> On 12/16/2015 09:22 AM, Andres Freund wrote:
>>
>> On 2015-12-16 18:21:47 +0100, Magnus Hagander wrote:
>>
>> Either they've found a way to script-generate gmail addresses, or
>> they have
>> found a way to break the django hashes.
>>
>>
>> Or they just hired somebody to do that kind of thing manually. There's
>> sites for that...
>>
>>
>>
>>
>> In the interim, let's just disable edits.
>>
>>
>> New account signups have been temporarily disabled at least. But yes, they
>> still have all those accounts against the wiki as well.
>
> What is the plan for undoing the spam edits?

we are working on that, but we have no final answer yet...

Stefan


From: Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc>
To: Bruce Momjian <bruce(at)momjian(dot)us>
Cc: Magnus Hagander <magnus(at)hagander(dot)net>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Andres Freund <andres(at)anarazel(dot)de>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 18:38:01
Message-ID: 5671AF89.6050303@kaltenbrunner.cc
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On 12/16/2015 07:12 PM, Stefan Kaltenbrunner wrote:
> On 12/16/2015 06:29 PM, Bruce Momjian wrote:
>> On Wed, Dec 16, 2015 at 06:28:18PM +0100, Magnus Hagander wrote:
>>> On Wed, Dec 16, 2015 at 6:27 PM, Joshua D. Drake <jd(at)commandprompt(dot)com> wrote:
>>>
>>> On 12/16/2015 09:22 AM, Andres Freund wrote:
>>>
>>> On 2015-12-16 18:21:47 +0100, Magnus Hagander wrote:
>>>
>>> Either they've found a way to script-generate gmail addresses, or
>>> they have
>>> found a way to break the django hashes.
>>>
>>>
>>> Or they just hired somebody to do that kind of thing manually. There's
>>> sites for that...
>>>
>>>
>>>
>>>
>>> In the interim, let's just disable edits.
>>>
>>>
>>> New account signups have been temporarily disabled at least. But yes, they
>>> still have all those accounts against the wiki as well.
>>
>> What is the plan for undoing the spam edits?
>
> we are working on that, but we have no final answer yet...

we are currently working on reverting the entire wiki back to a state
before the attack from system backups because it does not seem sensible
to try to revert this in piece meal style.

Stefan


From: Bruce Momjian <bruce(at)momjian(dot)us>
To: Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc>
Cc: Magnus Hagander <magnus(at)hagander(dot)net>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Andres Freund <andres(at)anarazel(dot)de>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 18:49:16
Message-ID: 20151216184916.GA15892@momjian.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Wed, Dec 16, 2015 at 07:38:01PM +0100, Stefan Kaltenbrunner wrote:
> >>> New account signups have been temporarily disabled at least. But yes, they
> >>> still have all those accounts against the wiki as well.
> >>
> >> What is the plan for undoing the spam edits?
> >
> > we are working on that, but we have no final answer yet...
>
> we are currently working on reverting the entire wiki back to a state
> before the attack from system backups because it does not seem sensible
> to try to revert this in piece meal style.

Agreed.

--
Bruce Momjian <bruce(at)momjian(dot)us> http://momjian.us
EnterpriseDB http://enterprisedb.com

+ As you are, so once was I. As I am, so you will be. +
+ Roman grave inscription +


From: Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc>
To: Bruce Momjian <bruce(at)momjian(dot)us>
Cc: Magnus Hagander <magnus(at)hagander(dot)net>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Andres Freund <andres(at)anarazel(dot)de>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 18:49:55
Message-ID: 5671B253.4010405@kaltenbrunner.cc
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On 12/16/2015 07:38 PM, Stefan Kaltenbrunner wrote:
> On 12/16/2015 07:12 PM, Stefan Kaltenbrunner wrote:
>> On 12/16/2015 06:29 PM, Bruce Momjian wrote:
>>> On Wed, Dec 16, 2015 at 06:28:18PM +0100, Magnus Hagander wrote:
>>>> On Wed, Dec 16, 2015 at 6:27 PM, Joshua D. Drake <jd(at)commandprompt(dot)com> wrote:
>>>>
>>>> On 12/16/2015 09:22 AM, Andres Freund wrote:
>>>>
>>>> On 2015-12-16 18:21:47 +0100, Magnus Hagander wrote:
>>>>
>>>> Either they've found a way to script-generate gmail addresses, or
>>>> they have
>>>> found a way to break the django hashes.
>>>>
>>>>
>>>> Or they just hired somebody to do that kind of thing manually. There's
>>>> sites for that...
>>>>
>>>>
>>>>
>>>>
>>>> In the interim, let's just disable edits.
>>>>
>>>>
>>>> New account signups have been temporarily disabled at least. But yes, they
>>>> still have all those accounts against the wiki as well.
>>>
>>> What is the plan for undoing the spam edits?
>>
>> we are working on that, but we have no final answer yet...
>
> we are currently working on reverting the entire wiki back to a state
> before the attack from system backups because it does not seem sensible
> to try to revert this in piece meal style.

we have now restored a backup from ~2015-12-15 05:00:37 UTC (later
backups already had spam traces in it) - th wiki is live again, user
account signup for the entire community account system is still disabled
until we have a better plan to deal with this crap.

Stefan


From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc>
Cc: Bruce Momjian <bruce(at)momjian(dot)us>, Magnus Hagander <magnus(at)hagander(dot)net>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Andres Freund <andres(at)anarazel(dot)de>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 18:53:22
Message-ID: 14062.1450292002@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc> writes:
>> we are currently working on reverting the entire wiki back to a state
>> before the attack from system backups because it does not seem sensible
>> to try to revert this in piece meal style.

> we have now restored a backup from ~2015-12-15 05:00:37 UTC (later
> backups already had spam traces in it) - th wiki is live again, user
> account signup for the entire community account system is still disabled
> until we have a better plan to deal with this crap.

"Recent changes" log says there's still at least one active spammer
account.

regards, tom lane


From: Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: Bruce Momjian <bruce(at)momjian(dot)us>, Magnus Hagander <magnus(at)hagander(dot)net>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Andres Freund <andres(at)anarazel(dot)de>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 19:24:09
Message-ID: 5671BA59.50604@kaltenbrunner.cc
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On 12/16/2015 07:53 PM, Tom Lane wrote:
> Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc> writes:
>>> we are currently working on reverting the entire wiki back to a state
>>> before the attack from system backups because it does not seem sensible
>>> to try to revert this in piece meal style.
>
>> we have now restored a backup from ~2015-12-15 05:00:37 UTC (later
>> backups already had spam traces in it) - th wiki is live again, user
>> account signup for the entire community account system is still disabled
>> until we have a better plan to deal with this crap.
>
> "Recent changes" log says there's still at least one active spammer
> account.

yeah thanks for letting us know - the problem is that it looks like the
spammers have pre-created (but not "used" until very recently) a lot of
accounts in the community account system over the last few days (if not
for much longer) and it is not really obvious which ones are "bad" and
which ones are not - we keep working on it :(

Stefan


From: Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: Bruce Momjian <bruce(at)momjian(dot)us>, Magnus Hagander <magnus(at)hagander(dot)net>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Andres Freund <andres(at)anarazel(dot)de>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-16 20:24:40
Message-ID: 5671C888.3050305@kaltenbrunner.cc
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On 12/16/2015 08:24 PM, Stefan Kaltenbrunner wrote:
> On 12/16/2015 07:53 PM, Tom Lane wrote:
>> Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc> writes:
>>>> we are currently working on reverting the entire wiki back to a state
>>>> before the attack from system backups because it does not seem sensible
>>>> to try to revert this in piece meal style.
>>
>>> we have now restored a backup from ~2015-12-15 05:00:37 UTC (later
>>> backups already had spam traces in it) - th wiki is live again, user
>>> account signup for the entire community account system is still disabled
>>> until we have a better plan to deal with this crap.
>>
>> "Recent changes" log says there's still at least one active spammer
>> account.
>
> yeah thanks for letting us know - the problem is that it looks like the
> spammers have pre-created (but not "used" until very recently) a lot of
> accounts in the community account system over the last few days (if not
> for much longer) and it is not really obvious which ones are "bad" and
> which ones are not - we keep working on it :(

I think we have it under control now - we have disabled ~200
"suspicious" community accounts, restored a backup of the wiki from ~36h
ago and nuked all the session data from the community auth system and
the wiki to prevent users from reusing existing sessions.
That seems to stablized the situation for now but community auth account
creation is still disabled.

We are currently discussion further actions which will likely involve
adding additional verification for community auth signup and maybe for
posting to the wiki. We are also looking into restoring the handful of
"valid" changes to the wiki between the time of the backup and the time
we restored it.

Stefan


From: Guillaume Lelarge <guillaume(at)lelarge(dot)info>
To: Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc>
Cc: Andres Freund <andres(at)anarazel(dot)de>, pgsql-www <pgsql-www(at)postgresql(dot)org>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, Bruce Momjian <bruce(at)momjian(dot)us>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Magnus Hagander <magnus(at)hagander(dot)net>
Subject: Re: Spam on the wiki
Date: 2015-12-16 20:48:58
Message-ID: CAECtzeUN5QHW-P83fw-34yCbn9vMxR4Y79DAX21Gryt3HmcSZw@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

Le 16 déc. 2015 9:24 PM, "Stefan Kaltenbrunner" <stefan(at)kaltenbrunner(dot)cc> a
écrit :
>
> On 12/16/2015 08:24 PM, Stefan Kaltenbrunner wrote:
> > On 12/16/2015 07:53 PM, Tom Lane wrote:
> >> Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc> writes:
> >>>> we are currently working on reverting the entire wiki back to a state
> >>>> before the attack from system backups because it does not seem
sensible
> >>>> to try to revert this in piece meal style.
> >>
> >>> we have now restored a backup from ~2015-12-15 05:00:37 UTC (later
> >>> backups already had spam traces in it) - th wiki is live again, user
> >>> account signup for the entire community account system is still
disabled
> >>> until we have a better plan to deal with this crap.
> >>
> >> "Recent changes" log says there's still at least one active spammer
> >> account.
> >
> > yeah thanks for letting us know - the problem is that it looks like the
> > spammers have pre-created (but not "used" until very recently) a lot of
> > accounts in the community account system over the last few days (if not
> > for much longer) and it is not really obvious which ones are "bad" and
> > which ones are not - we keep working on it :(
>
> I think we have it under control now - we have disabled ~200
> "suspicious" community accounts, restored a backup of the wiki from ~36h
> ago and nuked all the session data from the community auth system and
> the wiki to prevent users from reusing existing sessions.
> That seems to stablized the situation for now but community auth account
> creation is still disabled.
>
> We are currently discussion further actions which will likely involve
> adding additional verification for community auth signup and maybe for
> posting to the wiki. We are also looking into restoring the handful of
> "valid" changes to the wiki between the time of the backup and the time
> we restored it.
>

Thanks Stefan for all the hard work.


From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Guillaume Lelarge <guillaume(at)lelarge(dot)info>
Cc: Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc>, Andres Freund <andres(at)anarazel(dot)de>, pgsql-www <pgsql-www(at)postgresql(dot)org>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Bruce Momjian <bruce(at)momjian(dot)us>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Magnus Hagander <magnus(at)hagander(dot)net>
Subject: Re: Spam on the wiki
Date: 2015-12-16 20:58:49
Message-ID: 18669.1450299529@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

Guillaume Lelarge <guillaume(at)lelarge(dot)info> writes:
> Le 16 dc. 2015 9:24 PM, "Stefan Kaltenbrunner" <stefan(at)kaltenbrunner(dot)cc> a
> crit :
>> I think we have it under control now - we have disabled ~200
>> "suspicious" community accounts, restored a backup of the wiki from ~36h
>> ago and nuked all the session data from the community auth system and
>> the wiki to prevent users from reusing existing sessions.
>> That seems to stablized the situation for now but community auth account
>> creation is still disabled.
>>
>> We are currently discussion further actions which will likely involve
>> adding additional verification for community auth signup and maybe for
>> posting to the wiki. We are also looking into restoring the handful of
>> "valid" changes to the wiki between the time of the backup and the time
>> we restored it.

> Thanks Stefan for all the hard work.

Indeed, and Alvaro too. I'm sure you guys had better things to be doing
today :-(

regards, tom lane


From: Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: Guillaume Lelarge <guillaume(at)lelarge(dot)info>, Andres Freund <andres(at)anarazel(dot)de>, pgsql-www <pgsql-www(at)postgresql(dot)org>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Bruce Momjian <bruce(at)momjian(dot)us>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Magnus Hagander <magnus(at)hagander(dot)net>
Subject: Re: Spam on the wiki
Date: 2015-12-16 21:02:36
Message-ID: 5671D16C.1040507@kaltenbrunner.cc
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On 12/16/2015 09:58 PM, Tom Lane wrote:
> Guillaume Lelarge <guillaume(at)lelarge(dot)info> writes:
>> Le 16 déc. 2015 9:24 PM, "Stefan Kaltenbrunner" <stefan(at)kaltenbrunner(dot)cc> a
>> écrit :
>>> I think we have it under control now - we have disabled ~200
>>> "suspicious" community accounts, restored a backup of the wiki from ~36h
>>> ago and nuked all the session data from the community auth system and
>>> the wiki to prevent users from reusing existing sessions.
>>> That seems to stablized the situation for now but community auth account
>>> creation is still disabled.
>>>
>>> We are currently discussion further actions which will likely involve
>>> adding additional verification for community auth signup and maybe for
>>> posting to the wiki. We are also looking into restoring the handful of
>>> "valid" changes to the wiki between the time of the backup and the time
>>> we restored it.
>
>> Thanks Stefan for all the hard work.
>
> Indeed, and Alvaro too. I'm sure you guys had better things to be doing
> today :-(

thanks - but we actually had every single member of the sysadmin team
involved in this incident at some point...
The followup work of implementing additional verification and maybe
moderation steps are probably going to create even more work though.

Stefan


From: Peter Geoghegan <pg(at)heroku(dot)com>
To: Guillaume Lelarge <guillaume(at)lelarge(dot)info>
Cc: Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc>, Andres Freund <andres(at)anarazel(dot)de>, pgsql-www <pgsql-www(at)postgresql(dot)org>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, Bruce Momjian <bruce(at)momjian(dot)us>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Magnus Hagander <magnus(at)hagander(dot)net>
Subject: Re: Spam on the wiki
Date: 2015-12-16 21:17:23
Message-ID: CAM3SWZSX57fw8PHo=LpUMsGNjBgKbKV-J+XpJY27cfoaQmTGrw@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Wed, Dec 16, 2015 at 12:48 PM, Guillaume Lelarge
<guillaume(at)lelarge(dot)info> wrote:
> Thanks Stefan for all the hard work.

Thanks, Stefan.

--
Peter Geoghegan


From: "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>
To: Peter Geoghegan <pg(at)heroku(dot)com>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>
Cc: Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc>, Andres Freund <andres(at)anarazel(dot)de>, pgsql-www <pgsql-www(at)postgresql(dot)org>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, Bruce Momjian <bruce(at)momjian(dot)us>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Magnus Hagander <magnus(at)hagander(dot)net>
Subject: Re: Spam on the wiki
Date: 2015-12-16 22:45:44
Message-ID: 5671E998.5040609@commandprompt.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On 12/16/2015 01:17 PM, Peter Geoghegan wrote:
> On Wed, Dec 16, 2015 at 12:48 PM, Guillaume Lelarge
> <guillaume(at)lelarge(dot)info> wrote:
>> Thanks Stefan for all the hard work.
>
> Thanks, Stefan.
>
>

As someone who used to be on the infrastructure team, these guys are war
heroes. It is easy to forget the hard work they put in so that the rest
of us can enjoy this community.

Thanks folks!

JD

--
Command Prompt, Inc. - http://www.commandprompt.com/ 503-667-4564
PostgreSQL Centered full stack support, consulting and development.
Announcing "I'm offended" is basically telling the world you can't
control your own emotions, so everyone else should do it for you.


From: "Charles Clavadetscher" <clavadetscher(at)swisspug(dot)org>
To: "'Joshua D(dot) Drake'" <jd(at)commandprompt(dot)com>, "'Peter Geoghegan'" <pg(at)heroku(dot)com>, "'Guillaume Lelarge'" <guillaume(at)lelarge(dot)info>
Cc: "'Stefan Kaltenbrunner'" <stefan(at)kaltenbrunner(dot)cc>, "'Andres Freund'" <andres(at)anarazel(dot)de>, "'pgsql-www'" <pgsql-www(at)postgresql(dot)org>, "'Tom Lane'" <tgl(at)sss(dot)pgh(dot)pa(dot)us>, "'Bruce Momjian'" <bruce(at)momjian(dot)us>, "'Kevin Grittner'" <kgrittn(at)gmail(dot)com>, "'Dave Page'" <dpage(at)pgadmin(dot)org>, "'Magnus Hagander'" <magnus(at)hagander(dot)net>
Subject: Re: Spam on the wiki
Date: 2015-12-17 06:46:57
Message-ID: 00b301d13896$ca2ea740e8bf5c0$@swisspug.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: Postg스포츠 토토 사이트SQL : Postg스포츠 토토 사이트SQL 메일 링리스트 : 2015-12-17 이후 PGSQL WWW

> As someone who used to be on the infrastructure team, these guys are war
> heroes. It is easy to forget the hard work they put in so that the rest
> of us can enjoy this community.
>
> Thanks folks!
>
> JD

++1


From: Magnus Hagander <magnus(at)hagander(dot)net>
To: "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>
Cc: Andres Freund <andres(at)anarazel(dot)de>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-17 13:13:28
Message-ID: CABUevEw=dsvnJSCKMdV1DT6Hgzweo_-JUNekxj3=VVxPYZgYbA@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Wed, Dec 16, 2015 at 6:28 PM, Magnus Hagander <magnus(at)hagander(dot)net>
wrote:

> On Wed, Dec 16, 2015 at 6:27 PM, Joshua D. Drake <jd(at)commandprompt(dot)com>
> wrote:
>
>> On 12/16/2015 09:22 AM, Andres Freund wrote:
>>
>>> On 2015-12-16 18:21:47 +0100, Magnus Hagander wrote:
>>>
>>>> Either they've found a way to script-generate gmail addresses, or they
>>>> have
>>>> found a way to break the django hashes.
>>>>
>>>
>>> Or they just hired somebody to do that kind of thing manually. There's
>>> sites for that...
>>>
>>>
>>>
>> In the interim, let's just disable edits.
>
>
> New account signups have been temporarily disabled at least. But yes, they
> still have all those accounts against the wiki as well.
>
>
New account signups have been re-enabled, now requiring a captcha.
Hopefully that will be enough to stop the new spam signups. We'll keep an
eye on it and disable them again if it seems to happen again.

--
Magnus Hagander
Me: http://www.hagander.net/
Work: http://www.redpill-linpro.com/


From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Magnus Hagander <magnus(at)hagander(dot)net>
Cc: "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Andres Freund <andres(at)anarazel(dot)de>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-17 14:30:31
Message-ID: 29814.1450362631@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

Magnus Hagander <magnus(at)hagander(dot)net> writes:
> New account signups have been re-enabled, now requiring a captcha.
> Hopefully that will be enough to stop the new spam signups. We'll keep an
> eye on it and disable them again if it seems to happen again.

You probably already noticed, but ... they're at it again.

regards, tom lane


From: Magnus Hagander <magnus(at)hagander(dot)net>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Andres Freund <andres(at)anarazel(dot)de>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-17 14:39:41
Message-ID: CABUevEwKHwG7U0NZfKOu=anLFDJx8Vr3MS909m4YqzksEgL5zQ@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Thu, Dec 17, 2015 at 3:30 PM, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us> wrote:

> Magnus Hagander <magnus(at)hagander(dot)net> writes:
> > New account signups have been re-enabled, now requiring a captcha.
> > Hopefully that will be enough to stop the new spam signups. We'll keep an
> > eye on it and disable them again if it seems to happen again.
>
> You probably already noticed, but ... they're at it again.
>

ARGH!

I was looking at a cached copy of the page :S

--
Magnus Hagander
Me: http://www.hagander.net/
Work: http://www.redpill-linpro.com/


From: Magnus Hagander <magnus(at)hagander(dot)net>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Andres Freund <andres(at)anarazel(dot)de>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-17 15:01:52
Message-ID: CABUevEyCKJrEiOYauoGQZXUexHMZWsKqgqeU5eubO-E=sBsezw@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Thu, Dec 17, 2015 at 3:39 PM, Magnus Hagander <magnus(at)hagander(dot)net>
wrote:

>
>
> On Thu, Dec 17, 2015 at 3:30 PM, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us> wrote:
>
>> Magnus Hagander <magnus(at)hagander(dot)net> writes:
>> > New account signups have been re-enabled, now requiring a captcha.
>> > Hopefully that will be enough to stop the new spam signups. We'll keep
>> an
>> > eye on it and disable them again if it seems to happen again.
>>
>> You probably already noticed, but ... they're at it again.
>>
>
> ARGH!
>
> I was looking at a cached copy of the page :S
>
>
So they break the captcha in seconds. I'm more and more thinking andres'
idea that it's actually farmed out to people and not just bots...

I've shut the wiki down for the moment, pending that somebody who actually
knows anything about mediawiki shows up..

My suggestion is we make all edits on the wiki moderated, if that's at all
possible. It's AFAIK the only service where we allow people to post things
with no moderation on the content today, and clearly that's not working.
People will still be signing up accounts, but they can't do any damage with
them...

--
Magnus Hagander
Me: http://www.hagander.net/
Work: http://www.redpill-linpro.com/


From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Magnus Hagander <magnus(at)hagander(dot)net>
Cc: "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Andres Freund <andres(at)anarazel(dot)de>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-17 15:11:37
Message-ID: 31035.1450365097@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

Magnus Hagander <magnus(at)hagander(dot)net> writes:
> So they break the captcha in seconds. I'm more and more thinking andres'
> idea that it's actually farmed out to people and not just bots...

Yeah, it's sounding a lot like manual creation of the accounts and then
bots doing the actual spamming.

> My suggestion is we make all edits on the wiki moderated, if that's at all
> possible. It's AFAIK the only service where we allow people to post things
> with no moderation on the content today, and clearly that's not working.

Sigh. That's pretty ugly, though maybe it will work if you can set it up
so that known members of the community can bypass the moderation. The
bulk of the legitimate edits probably come from a fairly small number of
people.

regards, tom lane


From: Magnus Hagander <magnus(at)hagander(dot)net>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Andres Freund <andres(at)anarazel(dot)de>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-17 15:13:55
Message-ID: CABUevExCaBm5fWnqbEYoB-oamGRiTYkKV0BAXDt95g6Vm70i4g@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: Postg젠 토토SQL : Postg젠 토토SQL 메일 링리스트 : 2015-12-17 이후 PGSQL WWW 15:13

On Thu, Dec 17, 2015 at 4:11 PM, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us> wrote:

> Magnus Hagander <magnus(at)hagander(dot)net> writes:
> > So they break the captcha in seconds. I'm more and more thinking andres'
> > idea that it's actually farmed out to people and not just bots...
>
> Yeah, it's sounding a lot like manual creation of the accounts and then
> bots doing the actual spamming.
>

Yup.

> > My suggestion is we make all edits on the wiki moderated, if that's at
> all
> > possible. It's AFAIK the only service where we allow people to post
> things
> > with no moderation on the content today, and clearly that's not working.
>
> Sigh. That's pretty ugly, though maybe it will work if you can set it up
> so that known members of the community can bypass the moderation. The
> bulk of the legitimate edits probably come from a fairly small number of
> people.
>

Yeah. I have no idea how mediawiki actually works with those things, but
I'm not sure what else we can do. It's been suggested to have a cooling-off
period for new accounts, but how long should that be... I guess we could
have a 2-4 week cooling off period and then some way to bypass it by
contacting someone manually, but who's going to deal with those approvals?

--
Magnus Hagander
Me: http://www.hagander.net/
Work: http://www.redpill-linpro.com/


From: Euler Taveira <euler(at)timbira(dot)com(dot)br>
To: Magnus Hagander <magnus(at)hagander(dot)net>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Andres Freund <andres(at)anarazel(dot)de>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-17 15:18:47
Message-ID: 5672D257.7020001@timbira.com.br
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On 17-12-2015 12:13, Magnus Hagander wrote:
> Yeah. I have no idea how mediawiki actually works with those things, but
> I'm not sure what else we can do. It's been suggested to have a
> cooling-off period for new accounts, but how long should that be... I
> guess we could have a 2-4 week cooling off period and then some way to
> bypass it by contacting someone manually, but who's going to deal with
> those approvals?
>
Why don't we create a group of known community members? This group can
edit without restriction but new accounts will be moderated.

--
Euler Taveira Timbira - http://www.timbira.com.br/
PostgreSQL: Consultoria, Desenvolvimento, Suporte 24x7 e Treinamento


From: Magnus Hagander <magnus(at)hagander(dot)net>
To: Euler Taveira <euler(at)timbira(dot)com(dot)br>
Cc: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Andres Freund <andres(at)anarazel(dot)de>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-17 15:19:38
Message-ID: CABUevEzy0Q8cBoP2S3_9PCtQze_MsL25oh=vwMpxeOZ3v3n29A@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Thu, Dec 17, 2015 at 4:18 PM, Euler Taveira <euler(at)timbira(dot)com(dot)br> wrote:

> On 17-12-2015 12:13, Magnus Hagander wrote:
> > Yeah. I have no idea how mediawiki actually works with those things, but
> > I'm not sure what else we can do. It's been suggested to have a
> > cooling-off period for new accounts, but how long should that be... I
> > guess we could have a 2-4 week cooling off period and then some way to
> > bypass it by contacting someone manually, but who's going to deal with
> > those approvals?
> >
> Why don't we create a group of known community members? This group can
> edit without restriction but new accounts will be moderated.
>

Yeah, that might be the reasonable thing to do. We can probably cover 90+%
of all edits by such a solution. But somebody still has to clean up the
crap in the moderation queue.

--
Magnus Hagander
Me: http://www.hagander.net/
Work: http://www.redpill-linpro.com/


From: Andres Freund <andres(at)anarazel(dot)de>
To: Magnus Hagander <magnus(at)hagander(dot)net>
Cc: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Dave Page <dpage(at)pgadmin(dot)org>, Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-17 15:21:22
Message-ID: 20151217152122.GC2224@awork2.anarazel.de
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On 2015-12-17 16:01:52 +0100, Magnus Hagander wrote:
> I've shut the wiki down for the moment, pending that somebody who actually
> knows anything about mediawiki shows up..

I've not dealt with this in years, so I might be completely out of date
here. But I think adding something like
$wgGroupPermissions['*']['edit'] = false;
in the config ought to do the trick.

Then we can add a 'approved users' group, and give those edit
permissions. Not perfect, but ought to do as a first step.

Andres


From: Dave Page <dpage(at)pgadmin(dot)org>
To: Andres Freund <andres(at)anarazel(dot)de>
Cc: Magnus Hagander <magnus(at)hagander(dot)net>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-17 17:16:27
Message-ID: CA+OCxowi5C+xey9KMCo2ECSUisY4n-L36MJrx2Zt2+h_aAVifA@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Thu, Dec 17, 2015 at 3:21 PM, Andres Freund <andres(at)anarazel(dot)de> wrote:
> On 2015-12-17 16:01:52 +0100, Magnus Hagander wrote:
>> I've shut the wiki down for the moment, pending that somebody who actually
>> knows anything about mediawiki shows up..
>
> I've not dealt with this in years, so I might be completely out of date
> here. But I think adding something like
> $wgGroupPermissions['*']['edit'] = false;
> in the config ought to do the trick.
>
> Then we can add a 'approved users' group, and give those edit
> permissions. Not perfect, but ought to do as a first step.

Thanks - I've done something along those lines, and we've added the
active users from the last 30 days to a new editor group. If anyone
else wants to be added, they'll need to send email to request it for
the time being.

--
Dave Page
Blog: http://pgsnake.blogspot.com
Twitter: @pgsnake

EnterpriseDB UK: http://www.enterprisedb.com
The Enterprise PostgreSQL Company


From: Peter Geoghegan <pg(at)heroku(dot)com>
To: Dave Page <dpage(at)pgadmin(dot)org>
Cc: Andres Freund <andres(at)anarazel(dot)de>, Magnus Hagander <magnus(at)hagander(dot)net>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-17 19:32:56
Message-ID: CAM3SWZQAP35sVMtxuADL2y5yAPvhRioU0SS=ZdfG7S_eo2FUGg@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Thu, Dec 17, 2015 at 9:16 AM, Dave Page <dpage(at)pgadmin(dot)org> wrote:
> Thanks - I've done something along those lines, and we've added the
> active users from the last 30 days to a new editor group. If anyone
> else wants to be added, they'll need to send email to request it for
> the time being.

Seems reasonable, at least as an interim measure. I doubt we benefit
too much from "drive by" wiki edits.

--
Peter Geoghegan


From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Peter Geoghegan <pg(at)heroku(dot)com>
Cc: Dave Page <dpage(at)pgadmin(dot)org>, Andres Freund <andres(at)anarazel(dot)de>, Magnus Hagander <magnus(at)hagander(dot)net>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-17 19:38:05
Message-ID: 14731.1450381085@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

Peter Geoghegan <pg(at)heroku(dot)com> writes:
> On Thu, Dec 17, 2015 at 9:16 AM, Dave Page <dpage(at)pgadmin(dot)org> wrote:
>> Thanks - I've done something along those lines, and we've added the
>> active users from the last 30 days to a new editor group. If anyone
>> else wants to be added, they'll need to send email to request it for
>> the time being.

> Seems reasonable, at least as an interim measure. I doubt we benefit
> too much from "drive by" wiki edits.

Clarification please: is there a moderation queue in place now for edits
from non-editor users, or are they just summarily refused?

regards, tom lane


From: Bruce Momjian <bruce(at)momjian(dot)us>
To: Peter Geoghegan <pg(at)heroku(dot)com>
Cc: Dave Page <dpage(at)pgadmin(dot)org>, Andres Freund <andres(at)anarazel(dot)de>, Magnus Hagander <magnus(at)hagander(dot)net>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-17 20:21:58
Message-ID: 20151217202158.GA27806@momjian.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Thu, Dec 17, 2015 at 11:32:56AM -0800, Peter Geoghegan wrote:
> On Thu, Dec 17, 2015 at 9:16 AM, Dave Page <dpage(at)pgadmin(dot)org> wrote:
> > Thanks - I've done something along those lines, and we've added the
> > active users from the last 30 days to a new editor group. If anyone
> > else wants to be added, they'll need to send email to request it for
> > the time being.
>
> Seems reasonable, at least as an interim measure. I doubt we benefit
> too much from "drive by" wiki edits.

We do get "drive by" wiki edits on the TODO page.

--
Bruce Momjian <bruce(at)momjian(dot)us> http://momjian.us
EnterpriseDB http://enterprisedb.com

+ As you are, so once was I. As I am, so you will be. +
+ Roman grave inscription +


From: Peter Geoghegan <pg(at)heroku(dot)com>
To: Bruce Momjian <bruce(at)momjian(dot)us>
Cc: Dave Page <dpage(at)pgadmin(dot)org>, Andres Freund <andres(at)anarazel(dot)de>, Magnus Hagander <magnus(at)hagander(dot)net>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-17 20:23:01
Message-ID: CAM3SWZQhDZ-1UhpyBMej-T6+3csLdxv7MKPKqW-x3gEX-hFs_w@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Thu, Dec 17, 2015 at 12:21 PM, Bruce Momjian <bruce(at)momjian(dot)us> wrote:
> We do get "drive by" wiki edits on the TODO page.

I thought that they had to be discussed on list, first?

--
Peter Geoghegan


From: Bruce Momjian <bruce(at)momjian(dot)us>
To: Peter Geoghegan <pg(at)heroku(dot)com>
Cc: Dave Page <dpage(at)pgadmin(dot)org>, Andres Freund <andres(at)anarazel(dot)de>, Magnus Hagander <magnus(at)hagander(dot)net>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-17 20:26:49
Message-ID: 20151217202649.GB27806@momjian.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

On Thu, Dec 17, 2015 at 12:23:01PM -0800, Peter Geoghegan wrote:
> On Thu, Dec 17, 2015 at 12:21 PM, Bruce Momjian <bruce(at)momjian(dot)us> wrote:
> > We do get "drive by" wiki edits on the TODO page.
>
> I thought that they had to be discussed on list, first?

Yes, they are, but my point is that these are often new people who are
discussing these ideas. There is of course no rush for them to get on
to the TODO list permanently.

--
Bruce Momjian <bruce(at)momjian(dot)us> http://momjian.us
EnterpriseDB http://enterprisedb.com

+ As you are, so once was I. As I am, so you will be. +
+ Roman grave inscription +


From: Dave Page <dpage(at)pgadmin(dot)org>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: Peter Geoghegan <pg(at)heroku(dot)com>, Andres Freund <andres(at)anarazel(dot)de>, Magnus Hagander <magnus(at)hagander(dot)net>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Kevin Grittner <kgrittn(at)gmail(dot)com>, Bruce Momjian <bruce(at)momjian(dot)us>, Guillaume Lelarge <guillaume(at)lelarge(dot)info>, pgsql-www <pgsql-www(at)postgresql(dot)org>
Subject: Re: Spam on the wiki
Date: 2015-12-17 21:53:36
Message-ID: F7EE37E6-8EFE-497A-90C3-133BB015235B@pgadmin.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-www

> On 17 Dec 2015, at 19:38, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us> wrote:
>
> Peter Geoghegan <pg(at)heroku(dot)com> writes:
>>> On Thu, Dec 17, 2015 at 9:16 AM, Dave Page <dpage(at)pgadmin(dot)org> wrote:
>>> Thanks - I've done something along those lines, and we've added the
>>> active users from the last 30 days to a new editor group. If anyone
>>> else wants to be added, they'll need to send email to request it for
>>> the time being.
>
>> Seems reasonable, at least as an interim measure. I doubt we benefit
>> too much from "drive by" wiki edits.
>
> Clarification please: is there a moderation queue in place now for edits
> from non-editor users, or are they just summarily refused?

They are refused at present. I've yet to find a moderation facility.