PDA

View Full Version : Recent attack.


evkl
04-16-2005, 04:38 PM
Big "Thank you" to Woopert for alerting me and then running reverts. We're still trying to mop up this guy and guarantee he doesn't ever register again.

~Evan

Blackjack Palazzo
04-16-2005, 04:45 PM
Hmm?

evkl
04-16-2005, 04:46 PM
'pedia suffered an attack. Just thanking those who've helped out with the aftereffects and letting people know.

Ledian_X
04-16-2005, 04:48 PM
Cleaning up some images he posted. I can't rename some od the things he changed.

L_X

Evil Figment
04-16-2005, 05:14 PM
Nobody touches anything ATM. We'll try to set up a more efficient way to clean it all up. Last thing we need is fifty people trying to rever everything at once and working at cross-purposes.

Zeta
04-16-2005, 05:15 PM
Considering his return, why don't we disable new users from signing up until we can find a more specific solution?

Evil Figment
04-16-2005, 05:17 PM
Because a certain (better not said out loud) by the name of Zhen Lin forgot to give anyone else the power to do that and He's offline right now!

evkl
04-16-2005, 05:23 PM
Archaic has it, but probably doesn't know how to use it even if he were on.

Ledian_X
04-16-2005, 05:35 PM
Guys..he's back

Evil Figment
04-16-2005, 05:40 PM
No, really?

Getting on MSN and warning me *there* might work better.

Zeta
04-16-2005, 05:41 PM
Can we just uplug the server?

After this, we have to make getting an account harder.

We should force some way of making people wait for approval or have to provide a valid email address or something.

Banning someon doesn't do shit when they can make another account less than a minute later.

Evil Figment
04-16-2005, 05:46 PM
I can'T do a thing myself beyond blocking hte fuckwit when they show up. Need Zhen or Arcy to do more.

Ice Rabbit
04-16-2005, 06:04 PM
Is it possible to SID ban him?
People could keep backups.

evkl
04-16-2005, 06:12 PM
SID ban?

Jshadias
04-16-2005, 07:00 PM
Is it possible to SID ban him?
People could keep backups.

rofl

only on NetBattle 8)

Archaic
04-16-2005, 07:31 PM
If worst came to worst, we could always simply restore the 'pedia from before the server issues from backups anyway. We'd prefer not to of course though, which is why we're fighting this bastard.

We *will* be forcing accounts to require approval soon. It's not something we ever wanted to do, but this guy is leaving us with no choice. We're certainly not going to cave into their (likely fake) demands. That'd only make us all the more vulnerable to this kind of attack.

birdboy2000
04-16-2005, 08:02 PM
http://bulbapedia.bulbagarden.net/wiki/User:BulbaBot_%28power_Nazi%29

I think he might have been going a bit overboard... Considering it's a @#$%ing BOT!

Archaic
04-16-2005, 08:07 PM
Hmmm....he might not be using a bot afterall...

Love to know why he thinks we don't like non sysops editing pages. It's not like people have been blocked at any point from editing, excepting when we're doing maintence. Hell, look at the TPM pages. Most of the editing done there wasn't even done by people with BMGf accounts!

☆欠番☆
04-16-2005, 08:23 PM
He called me a Power Nazi who doesn't like non-Sysops editing pages... but I'm not a Sysop...

Water Pokémon Master
04-16-2005, 08:24 PM
I hate attacks. It has happened to my site/forum before twice in the past. It's such a pain to clean up.

I hope you guys find out a solution to easily undo things like this in the future, such as if you delete a user, you can delete all of his/her posts (or in this case, edits). I wonder who did this? (has an idea, but does not want to wear out his stay already)

Archaic
04-16-2005, 08:25 PM
Once we have the IP, we'll know. We'll match it to forum databases, and also go through referrer logs to find out where he first learnt of Bulbapedia.

Archaic
04-16-2005, 08:45 PM
IP's located. Checks will now be run on BMGf to match to users, and bans will be made if necessary.

201.224.75.198
212.244.131.100
62.0.13.2
200.140.131.194
63.99.211.212
193.251.137.13
82.237.216.153
80.227.56.42
203.131.71.114

EDIT: As expected, the attacker was using proxies. A pity. We'll continue to do everything we can to track him down.

Water Pokémon Master
04-16-2005, 09:04 PM
If worst comes to worst, you could always look up their ISP and call them. Then if you give them the IP, they can tell you who they lent it to at the time.

Archaic
04-16-2005, 09:37 PM
Since he or she was using proxies, there's no way to do that sadly.

Zeta
04-16-2005, 10:18 PM
How does the regular Wikipedia handle these things, anyways?

evkl
04-16-2005, 10:29 PM
They usually don't get people using bots on a grand scale like this, methinks.

Jshadias
04-16-2005, 10:39 PM
of course they do lol, they just have a lot of sysops and other people to revert changes

Kadabra
04-16-2005, 10:45 PM
Simple fix that should have been there in place: Limit on the number of edit per unit time for an account. Of course, if you make it necessary to have new accounts approved, this won't be as needed.

Zhen Lin
04-17-2005, 12:36 AM
Edit throttling is around somewhere, I think. I've seen it before.

MediaWiki is highly admin-unfriendly. There is no web-based configuration, no web-based maintenance tools, and worse, no maintenance tools to deal with such massive vandalism. Wikipedia gets by fine because they have total control of the servers they use, have many technical operators, and many thousands of users pouncing on vandalism in seconds - so much so that automatic mass reversion is not needed.

In the meantime, congratulations to Zeta and Woopert! (http://bmgf.bulbagarden.net/showthread.php?p=116922)

Evil Figment
04-17-2005, 12:53 AM
Yesterday shall henceforth be known as the Great Bulbapedia Turkey Shoot.

Archaic
04-17-2005, 02:35 AM
Works for me.

*Creates Bulbapedia article, hoping that it's alright to use caps for all the words*

Anyone care to create the timeline of events?

Zhen Lin
04-17-2005, 02:45 AM
As a non-analytic name, it is a proper noun, so yes, the titling is correct.

Since the database has been almost totally purged of all traces of the attack, the timeline and details will have to be reconstructed from chat logs.

Archaic
04-17-2005, 07:26 AM
I'm sure we've got enough of those.

We'll have to reopen registrations to everyone eventually though I think. Taking away the ability to quickly register and edit something will really hamper the ability of casual users to edit articles on a whim I feel.

Kadabra
04-17-2005, 09:56 AM
/me wants to create an account ;_;
(This whole mess sparked by interest in the project. XD)

Archaic
04-17-2005, 10:16 AM
Sign up and I'll approve it then. ^_^

Kadabra
04-17-2005, 10:25 AM
I think the sign up form is hidden. Perhaps I'm still asleep. *_*
The user log in and registration page: http://bulbapedia.bulbagarden.net/w/index.php?title=Special:Userlogin&returnto=Special:Userlogin
Was the form hidden as a precaution?

Jshadias
04-18-2005, 02:24 AM
Yeah, the registration form is hidden to users who don't already have an account, or aren't sysops. imo you should just open registration to everyone again and have tools ready to clean these things up... having open registration will help us reach the point where the tools are hardly needed anyways. I also don't think that such a big deal should really have been made out of this; some script kiddy running a bot is nothing special.

Zhen Lin
04-18-2005, 02:48 AM
I know. As far as I am concerned, there is no further point in keeping registration locked.

Except maybe to frustrate the kid for a few more days until he gets bored and finds another target.