wiki@glassfish.java.net

Re: [gfwiki] URGENT: glassfish wiki has been vandalized

From: Tom Mueller <Tom.Mueller_at_Sun.COM>
Date: Wed, 26 Sep 2007 14:12:49 -0500

Jamey,
I don't see how this helps with this problem. The problem here is that
anyone can create an account without any permission. The words that are
going on the pages are random gibberish - we cannot prevent that type of
editing using the SpamFilter.

Tom


Jamey Wood wrote:
> Hi Tom,
>
> I've enabled JSPWiki's "SpamFilter"
> (http://jspwiki.org/wiki/SpamFilter), and populated its blacklist with
> some entries based on this spam. You guys can use the
> "PortalAdministrator" account to update the blacklist. (Dean should
> have the account info, if it hasn't already been passed along to you.)
>
> To do so, just update the "blacklist.txt" file at:
>
> http://wiki.portal.java.net/Wiki.jsp?page=SpamFilterWordList
>
> (which again, only admin users can do).
>
> Since we haven't used this before, we'll need to keep an eye on things
> to see how well it works. Let me know if you see any issues.
>
> --Jamey
>
> Tom Mueller wrote:
>> Eduardo, Jamey,
>>
>> The wiki.glassfish.java.net site has been vandalized. On the front
>> page, right under the fish, you'll see the following: "cadomc4t
>> eltgetc acoloacele daroutrboc delletopasno pasmondro tacalibor
>> relcacli". The same thing happened to the wiki.portal.java.net site;
>> I see suspect edits on at least 25 pages.
>>
>> Can we shut off account creation immediately on the portal wiki site
>> until we can resolve this issue? We also need to delete the suspect
>> accounts. For portal, these accounts are the following:
>>
>> <http://wiki.portal.java.net/Wiki.jsp?page=Communities>OrdarDronr
>> AcelrActrr
>> <http://wiki.portal.java.net/Wiki.jsp?page=Blogs>DellaZelsi
>> <http://wiki.portal.java.net/Wiki.jsp?page=PortletRepository>LatrzElget
>> <http://wiki.portal.java.net/Wiki.jsp?page=PortalInstallInstructions>ElbotRpasb
>> **OlovaRcrac
>> <http://wiki.portal.java.net/Wiki.jsp?page=SGDPortlet>LitroCdomz
>> <http://wiki.portal.java.net/Wiki.jsp?page=PortalB5InstallInstructions>DarelBastr
>> OloelBodar
>> <http://wiki.portal.java.net/Wiki.jsp?page=PortalBuildInstructions>TaoloBasno
>> <http://wiki.portal.java.net/Wiki.jsp?page=PortalProject.PortalObjectModel>
>>
>> DroncNamon
>> <http://wiki.portal.java.net/Wiki.jsp?page=PortletOwnersAndContributors>EltadRonbo
>> <http://wiki.portal.java.net/Wiki.jsp?page=WSRPDBConfig>C4ttrAccod
>> <http://wiki.portal.java.net/Wiki.jsp?page=PS72b6ReleaseNotes>LidelDombo
>> <http://wiki.portal.java.net/Wiki.jsp?page=WSRP>ElzelDronr
>> <http://wiki.portal.java.net/Wiki.jsp?page=PortletChallengeContest>OloelDomva
>> <http://wiki.portal.java.net/Wiki.jsp?page=PortalProject>TarelOuace
>> <http://wiki.portal.java.net/Wiki.jsp?page=PortletsInTheRepository>VaracEltrm
>> <http://wiki.portal.java.net/Wiki.jsp?page=PortalPack>
>> Zelc4Tbocr
>> <http://wiki.portal.java.net/Wiki.jsp?page=PortletWebServices>LirorOalri
>> CogetAlget CapasLaerc
>> <http://wiki.portal.java.net/Diff.jsp?page=CapasLaerc&r1=-1>
>> <http://wiki.portal.java.net/Wiki.jsp?page=DesktopWSRPReintegration>BocvaRelre
>> <http://wiki.portal.java.net/Wiki.jsp?page=OpenPortalModuleOwners>VioudElroa
>> <http://wiki.portal.java.net/Wiki.jsp?page=PortletContainer>ElgetAlrol
>> <http://wiki.portal.java.net/Wiki.jsp?page=PS72b7ReleaseNotes>NoacdEllar
>>
>> Thanks.
>> Tom
>>
>>
>> ------------------------------------------------------------------------
>>
>> ---------------------------------------------------------------------
>> To unsubscribe, e-mail: wiki-unsubscribe_at_glassfish.dev.java.net
>> For additional commands, e-mail: wiki-help_at_glassfish.dev.java.net
>>
>