maemo.org - Talk

maemo.org - Talk (https://talk.maemo.org/index.php)
-   Community (https://talk.maemo.org/forumdisplay.php?f=16)
-   -   Wiki got spammed (https://talk.maemo.org/showthread.php?t=93841)

British 2014-09-12 12:10

Wiki got spammed
 
2 Attachment(s)
Attached you'll find what I was greeted with earlier today when I checked the Firmware-updating wiki page.

It seems like the template Ambox was modified, which obviously explains the boxes, but I'm not sure about the "Flashing the eMMC in the N900" part, as that page wasn't modified...

Please take actions.


PS: I would gladly have reported this issue by regular channels, but I have no idea of what they actually are.

[Edit] The "Flashing..." part was actually a box, as can be seen here.

sixwheeledbeast 2014-09-12 13:06

Re: Wiki got spammed
 
Thank you.
I have repaired the issue.

British 2014-09-12 13:09

Re: Wiki got spammed
 
Good.

Did you hang the culprit ?
A public execution would be in order.

Ilew 2014-09-12 13:22

Re: Wiki got spammed
 
When I try to go to the wiki I get:
Couldn't authenticate against garage. (DB problem)

reinob 2014-09-12 14:13

Re: Wiki got spammed
 
Quote:

Originally Posted by British (Post 1439006)
Good.

Did you hang the culprit ?
A public execution would be in order.

I'd also be interested to know if this was an "inside job" (a maemo.org user) or an external attack.

Both cases would need (immediate) action.

nokiabot 2014-09-12 14:23

Re: Wiki got spammed
 
Why anyone would do that to our poor wiki ? :(

British 2014-09-12 14:42

Re: Wiki got spammed
 
Quote:

Originally Posted by nokiabot (Post 1439016)
Why anyone would do that to our poor wiki ? :(

You obviously only say that because you don't reckon how important UTW Garnicia Cambogia is !

endsormeans 2014-09-12 16:12

Re: Wiki got spammed
 
Hmm...I think you are on to something there British...

Perhaps someone figured the wiki needed to shed a few pounds and lose weight. :D

Unlikely tho that it was an inside job...

The average maemoite wouldn't sink so low...
and the wickedest-evil-genius would have done worse...
flooding us with Bieber-crap..
or (shudder) Kardashianspam...
or ...(horror) Honey Boo-Boo poo....

peterleinchen 2014-09-12 17:35

Re: Wiki got spammed
 
A quick whois at least gave the country of attacker:
Quote:

inetnum: 91.207.4.0 - 91.207.9.255
inetname: SteepHost-DC-UA
descr: PP Andrey Kiselev
remarks: SteepHost.COM Datacentre Allocation
remarks: +380-63-618-45-00
remarks: Please send all spam/scam/fraud abuse to abuse@steephost.com
country: UA
org: ORG-SH7-RIPE
admin-c: SH3855-RIPE
tech-c: SH3855-RIPE
status: ASSIGNED PI
mnt-by: RIPE-NCC-END-MNT
mnt-by: SH3855-MNT
mnt-lower: RIPE-NCC-END-MNT
mnt-routes: SH3855-MNT
mnt-domains: SH3855-MNT
source: RIPE # Filtered

organisation: ORG-SH7-RIPE
org-name: PP Andrey Kiselev
descr: PP Andrey Kiselev
org-type: OTHER
address: Kvartalniy str. 6/13, 37
address: 62418, Pesochin, Kharkivska, Ukraine
phone: +380-63-618-45-00
abuse-c: AR19187-RIPE
abuse-mailbox: abuse@steephost.com
mnt-ref: SH3855-MNT
mnt-by: SH3855-MNT
source: RIPE # Filtered

role: SteepHost DC-UA
address: Mironosickaya str., 76-b
address: 61023, Kharkiv, Ukraine
remarks: Routing and Peering requests............: noc@steephost.com
phone: +380-63-618-45-00
abuse-mailbox: abuse@steephost.com
admin-c: AK5709-RIPE
tech-c: AK5709-RIPE
nic-hdl: SH3855-RIPE
mnt-by: SH3855-MNT
source: RIPE # Filtered

% Information related to '91.207.5.0/24AS47142'

route: 91.207.5.0/24
descr: SteepHost DC-UA
descr: SteepHost.COM Datacentre Allocation
descr: +380-63-618-45-00
descr: Please send all spam/scam/fraud abuse to abuse@steephost.com
origin: AS47142
mnt-by: SH3855-MNT
source: RIPE # Filtered


Estel 2014-09-12 21:48

Re: Wiki got spammed
 
Quote:

Originally Posted by peterleinchen (Post 1439031)
A quick whois at least gave the country of attacker:
[/size]

...or his proxy ;)

nieldk 2014-09-13 06:14

Re: Wiki got spammed
 
Reported to techstaff

peterleinchen 2014-09-13 07:21

Re: Wiki got spammed
 
Quote:

Originally Posted by nieldk (Post 1439076)
Reported to techstaff

Oh :(
Good idea :) totally forgot ;)

But is it not you to check such things, too? :D

chemist 2014-09-13 16:14

Re: Wiki got spammed
 
In the meanwhile on techstaff channels:

Quote:

I checked the wiki's apache log and the attack we received was
made by many ip of the class 91.207.x.x.
They tried to edit all the templates until they managed to change a page while using 91.207.5.205

jellyroll 2014-09-13 16:28

Re: Wiki got spammed
 
It's very sad to read about the maemo wiki page being spammed while sitting at the MC Donalds and enjoying a tasty double cheese burger. I never understood those spammers anyway there must be some kind of borderline personality disorder involved to make them do these type of actions.

nieldk 2014-09-13 17:33

Re: Wiki got spammed
 
meanwhile.
I reported the spam to techstaff, only to be told I was pointing fingers.
Wont make that "mistake" again.

Good luck in finding out who did this, if simply posting "i reported" is fingerpointing, im out.

This was - in my opinion - a serious issue - and pointing fingers at who reports is not serious.

I will consider what this means to my involvement!

bye

thedead1440 2014-09-13 18:13

Re: Wiki got spammed
 
neildk,

IMO, as a community member, you should be posting such a log for all to see so that it doesn't paint all techstaff with the same brush and also adds some clarity to your words.

nieldk 2014-09-13 18:28

Re: Wiki got spammed
 
Quote:

Originally Posted by thedead1440 (Post 1439129)
neildk,

IMO, as a community member, you should be posting such a log for all to see so that it doesn't paint all techstaff with the same brush and also adds some clarity to your words.

I take what happened serious, and I wont point fingers at specific persons.
I will however discuss this with council, as well as board.
If the person being identified in another thread can be confirmed, it should have consequences, as should it not taking any clues into consideration.
It is quite normal to use whistleblowsers, and while some nay not like it, it is effective.
Now, I dont think poibting out individuals in public is the right thing to do, but I do believe giving any - even the slightest - hints to those responsible for incidents, in a closed loop, is the right action!

thedead1440 2014-09-13 18:57

Re: Wiki got spammed
 
Sorry I think I am missing the source of your frustration; is it you being put down for reporting a spam attack or is it because there was a disagreement regarding whodunnit?

I merely wanted you to paste a log for "if simply posting "i reported" is fingerpointing, im out." to understand why just reporting can be interpreted this way.

I still feel pasting of log without naming whodunnit is a transparent practice instead of it being hidden away between the few people in board and/or council...

nieldk 2014-09-13 19:11

Re: Wiki got spammed
 
the post in question was not by me (it was namibg a oerson of community)
That post have, I see, been removed.
This is good, persons are innocent, until proven guilty.
As for tech, I think they are all good, and responding in best intention.
There was a misunderstanding of who named a member as offending in a public post.
I reported the spam to tech - including that name - for investigation, and some persons thought I posted name in public post.
This IS now sorted out, and I do not want to name individuals, As I do not want any of our good staff to get offended and stop their good work.
It is human and it is very easy to misunderstand short mails, I am probably to blame as well for being too short of words in my report.
So, apologiges to tech members for that !
/Niel

thedead1440 2014-09-13 19:23

Re: Wiki got spammed
 
Quote:

Originally Posted by nieldk (Post 1439139)
It is human and it is very easy to misunderstand short mails, I am probably to blame as well for being too short of words in my report.
So, apologiges to tech members for that !
/Niel

Indeed... Anyway I hope you do re-think your approach of rage-quitting or posting a goodbye message every time you feel slighted (not referring to just this case) and then getting back in the fold once things are clearer. Calmer heads are always better after all :)

nieldk 2014-09-13 19:32

Re: Wiki got spammed
 
I have no intention of leaving.
I was considering how/if I would report, but, since this is now cleared. No sweat

Akkumaru 2014-09-14 08:52

Re: Wiki got spammed
 
The CSSU page also has this problem. It's at "Thumbers", "Features", "Changelogs", "QA and Bugs", and "Development"

peterleinchen 2014-09-14 11:50

Re: Wiki got spammed
 
This was a new attack executed from same IP range.
Corrected that in wiki.

xes 2014-09-14 19:18

Re: Wiki got spammed
 
Thank you all for your reports, we are evaluating and applying the blocks to stop this spam activity.

peterleinchen 2014-09-17 20:45

Re: Wiki got spammed
 
Another spammming.
Reported here.

xes 2014-09-17 23:45

Re: Wiki got spammed
 
New turn of the screw. Blacklists have been extended and merged from multiple sources to make spammer's life harder.

wicket 2014-09-18 04:41

Re: Wiki got spammed
 
Quote:

Originally Posted by xes (Post 1439572)
New turn of the screw. Blacklists have been extended and merged from multiple sources to make spammer's life harder.

It also makes Tor users lives harder. :(
Fair enough if it blocks Tor users from updating the wiki but I can't even view it now!

xes 2014-09-18 08:10

Re: Wiki got spammed
 
@wicket
There is no explicit will to block the tor network, but if one of their exit points is blacklisted because it's reported to be used for malicious activity i don't think we should create a whitelist for it.

If you have further details about the tor ip currently blocked we can make a check.

wicket 2014-09-18 16:47

Re: Wiki got spammed
 
Quote:

Originally Posted by xes (Post 1439586)
@wicket
There is no explicit will to block the tor network, but if one of their exit points is blacklisted because it's reported to be used for malicious activity i don't think we should create a whitelist for it.

If you have further details about the tor ip currently blocked we can make a check.

I realise this. Unfortunately the Tor network is frequently abused for malicious activity so it's not uncommon for Tor IP addresses to appear on blacklists.

I'm not so much interested in getting a specific Tor IP address unblocked. I'd prefer that the blocking occurs only when attempting to update the wiki rather block the entire site site so it can't be viewed. Another possible solution would be to implement some sort of human verification such as CAPTCHA when registering an account or updating the wiki.

bandora 2014-09-18 20:06

Re: Wiki got spammed
 
Quote:

Originally Posted by peterleinchen (Post 1439031)
A quick whois at least gave the country of attacker:
[/size]

It's Putin and his lads!! I KNEW IT.. :D

pichlo 2014-09-18 20:21

Re: Wiki got spammed
 
Has anyone complained to the IP owner? He may not even know that his infrastructure is being abused...

endsormeans 2014-09-18 20:25

Re: Wiki got spammed
 
I agree...
Very highly probable...

xes 2014-09-18 22:34

Re: Wiki got spammed
 
@pichlo
Today we blocked ~800 ip because they are known spammers blacklisted for malicious activities.
Are you suggesting that we should send to everyone an email to notify the kind of activity their hosts are doing? ..I don't think is possible.

pichlo 2014-09-18 23:49

Re: Wiki got spammed
 
Where does the number 800 comes from? AIUI, there was a small number of incidents on our wiki, each traced to a single IP address. But I may have of course missed something.

xes 2014-10-09 23:32

Re: Wiki got spammed
 
@wicket
Since it seems i failed explaining the situation i will try to let it crystal clear.

maemo.org is a nice set (mess) of servers and deeply customized services that after at least 4 generations of different setups/moves/migrations .... are now what you can see and use here.
When techstaff evaluates a change, MUST consider security, resources, man power and time required for the different options.

When you think to have the best solution to fix something, for example add a captcha, you don't know that it means update all mediawiki, port the customizations and install the proper addon.

On the other hand we have a bunch of robots trying to add spam and deleting wiki pages continuosly and a lot of good guys trying to understand if they can play the new game called shellshock here....

Now, while still waiting your tor exit point ip to discover if the blacklist has something weird...

Now that i have explained what is under the hood of the services you are using, please let me understand why if you are a good licit member of this community you need tor to browse or contribute to wiki hiding your real ip or userid.

juiceme 2014-10-10 05:10

Re: Wiki got spammed
 
Quote:

Originally Posted by xes (Post 1442512)
Now that i have explained what is under the hood of the services you are using, please let me understand why if you are a good licit member of this community you need tor to browse or contribute to wiki hiding your real ip or userid.

Actually this might also affect users not using tor, if they are running a tor exit node on their system.
It is always possible that your node gets blacklisted because of somebody else's bad behaviour using your tor node :(
Fortunately that has not happened to me yet.

wicket 2014-10-10 06:19

Re: Wiki got spammed
 
Quote:

Originally Posted by xes (Post 1442512)
Now that i have explained what is under the hood of the services you are using, please let me understand why if you are a good licit member of this community you need tor to browse or contribute to wiki hiding your real ip or userid.

xes, thank you for taking the time to reply. I appreciate that your job is voluntary and that the recent maemo.org spam attacks have come as an unwelcomed inconvenience.

Since the revelations of Edward Snowden I have taken internet privacy more seriously than ever before and as a consequence it has become natural to me that I should use Tor for all internet activity. Having to disable Tor just to read the wiki or bug tracker is an inconvenience. Preventing read-only access does not help in any way to prevent spammers. I would recommend a policy similar to Wikipaedia where everyone has read-only access and should someone wish to update the wiki they are required to either validate their identity by logging in or they must disable Tor entirely.

As I already said, I appreciate that your job is voluntary so I would say there's no rush to implement this but I would at least like an acknowledgement that this is something that would be achievable in the near future.

Cheers.

sixwheeledbeast 2014-10-10 07:11

Re: Wiki got spammed
 
Quote:

Originally Posted by wicket (Post 1442527)
As I already said, I appreciate that your job is voluntary so I would say there's no rush to implement this but I would at least like an acknowledgement that this is something that would be achievable in the near future.


There are ways to whitelist wiki.maemo.org for the time being.
I have Elite Proxy Switcher for Firefox which can switch proxy's with one click on the statusbar.
You could also put maemo.org in your no proxies list.

xes 2014-10-10 13:14

Re: Wiki got spammed
 
@wicket
i can see you are a reasonable guy and for me is a pleasure partecipate to this thread made of requests, actions and explanations, exactly in the spirit of this community.

There is already a plan to update wiki, but, you know, every member of techstaff has a real life and just a few hours of free time to engage big (dangerous) changes. Let's see how it proceeds.
Then, bugs is on the same server and even if updated, receives almost the same attacks of wiki so the actual dynamic blacklist protects both of them.

There are always many things to consider and while it's easy to make a wrong choice, often, also the better option is not perfect at the eyes of all.


All times are GMT. The time now is 01:33.

vBulletin® Version 3.8.8