<font style="font-family: courier new,monospace;" size="2"><a href="http://wiki.laptop.org">wiki.laptop.org</a> is being attacked much like <a href="http://wiki.sugarlabs.org">wiki.sugarlabs.org</a> was on 13 July 2010 between 11:21 and 19:22 EDT.<br>
<br>See <a href="http://wiki.laptop.org/go/Special:RecentChanges">http://wiki.laptop.org/go/Special:RecentChanges</a> for lines like this:<br><br> N ! 23:56 User talk:Whereresi (diff; hist) . . (+101) . . Whereresi (Talk | contribs | block) (Created page with 'wear, <a href="http://dotnetfreak.co.uk/members/Lilian_5F00_Devries.aspx">http://dotnetfreak.co.uk/members/Lilian_5F00_Devries.aspx</a> teeth whitening louisiana , sentence.')<br>
<br><br>Using OpenID for new accounts authentification seems to have ended the spamming at wiki.SL, although the autoblocking pattern visible here, <a href="http://wiki.laptop.org/go/Special:BlockList">http://wiki.laptop.org/go/Special:BlockList</a>, persists at wiki.SL.<br>
</font><font style="font-family: courier new,monospace;" size="2"><br></font><font style="font-family: courier new,monospace;" size="2"><br>See this post, <a href="http://lists.sugarlabs.org/private/systems/2010-July/002197.html">http://lists.sugarlabs.org/private/systems/2010-July/002197.html</a> if subscribed, or this extract:<br>
<br></font><blockquote style="margin: 0pt 0pt 0pt 0.8ex; border-left: 1px solid rgb(204, 204, 204); padding-left: 1ex; font-family: courier new,monospace;" class="gmail_quote"><font size="2">Almost 150 new accounts were opened, almost all placing spamming links in the Talk page. </font></blockquote>
<blockquote style="margin: 0pt 0pt 0pt 0.8ex; border-left: 1px solid rgb(204, 204, 204); padding-left: 1ex; font-family: courier new,monospace;" class="gmail_quote"><font size="2">See <a href="http://wiki.sugarlabs.org/go/Special:RecentChanges">http://wiki.sugarlabs.org/go/Special:RecentChanges</a> for that time range.<br>
</font></blockquote><blockquote style="margin: 0pt 0pt 0pt 0.8ex; border-left: 1px solid rgb(204, 204, 204); padding-left: 1ex; font-family: courier new,monospace;" class="gmail_quote"><pre><font size="2">At 18:03 I noticed the attack and blocked the most recent account.<br>
Immediately #369 was (Autoblocked because your IP address has been recently<br>used by "Eridalad".)<br><br>See <a href="http://wiki.sugarlabs.org/go/Special:BlockList">http://wiki.sugarlabs.org/go/Special:BlockList</a><br>
<br>After 5 similar cycles, at 18:35, I sent a note to<br><a href="http://lists.sugarlabs.org/listinfo/systems">webmaster at sugarlabs.orgwith</a> this message,<br><br>See <a href="http://wiki.sugarlabs.org/go/Special:RecentChanges">http://wiki.sugarlabs.org/go/Special:RecentChanges</a><br>
<br>...<br><br>- decided to disable wiki account creation with this in<br>LocalSettings.php<br><br># 2010-07-13 18:41:59 -0400 fgrose<br><br># Prevent new user registrations except by sysops<br><br># 2010-07-13 19:21:21 -0400 fgrose: commented out for testing<br>
<br># 2010-07-13 19:24:00 -0400 fgrose: reinhibit<br><br>$wgGroupPermissions['*']['createaccount'] = false;<br><br>...<br><br>The blocklist and the test at 19:21 showed that the attack had not stopped.<br>
(Notice the pattern of increasing odd number autoblocks.)<br><br>- updated <a href="http://wiki.sugarlabs.org/go/MediaWiki:Loginprompt">http://wiki.sugarlabs.org/go/MediaWiki:Loginprompt</a> to suggest<br>that new users create accounts with an OpenID.<br>
<br>This has prevented the spam, but the server and database may still be under<br>attack.<br><br> --Fred<br></font></pre></blockquote><br>