Forum:Mass Vandalisms 2

From Uncyclomedia, the UnMeta-wiki
Jump to: navigation, search
Forum: Home > Mass Vandalisms 2


Good afternoon, I come back UnCommons report that was victim of mass the vandalism during the last 12 hours. It would be a common thing if I had not noticed some similarities between the vandalisms

Last banned
  1. (Show / hide) 15:45, 18 August 2011 Rhubella Marie (Talk | contribs | block) blocked "Aulbine1978 (Talk | contribs)" with a long lasting forever (disabled creating user accounts) (Spamming to external sites.) (unlock | lock change)
  2. (Show / hide) 04:01, 18 August 2011 Rhubella Marie (Talk | contribs | block) blocked "Boril1962 (Talk | contribs)" with a long lasting forever (disabled creating user accounts) (Spamming to external sites.) (unlock | lock change)
  3. (Show / hide) 04:01, 18 August 2011 Rhubella Marie (Talk | contribs | block) blocked "Paindweller1988 (Talk | contribs)" with a long lasting forever (disabled creating user accounts) (Spamming to external sites.) (unlock | lock change)
  4. (Show / hide) 04:00, 18 August 2011 Rhubella Marie (Talk | contribs | block) blocked "Schneider1961 (Talk | contribs)" with a long lasting forever (disabled creating user accounts) (Spamming to external sites.) (unlock | lock change)

I believe it is the same person who had already vandalized earlier in February, both here and in UnCommons. Probably he should not have the opportunities as were with that crisis as a server and discovered the security tag blockade imposed by Carlb, decided to change tactics.

I think we have to take action on that sort of thing and go back to argue about have more administrators here and UnCommons. Rhubella beach.jpgRhubella Marie, the rat sockpreppie 2,347 preppieditsRhubella.jpg 16:03, 18 August 2011 (UTC)

These are most likely not persons but spambots (there is a pattern of spam registrations which are typically two words or names at random plus a number); not sure if this bug is adding to the problems, but I had added reCAPTCHA on initial registration a week or so ago in an attempt to stem the tide of "random words plus a number" accounts being created in bulk. It may be worth adding a "nuke" option to MediaWiki:Blockipsuccesstext as " [[User:$1|$1]] ([[User talk:$1|talk]] | [[{{ns:Special}}:Contributions/$1|contribs]] | [[{{ns:Special}}:Nuke/$1|nuke]]) has been blocked. " If spam accounts are being created to make new pages of worthless ads, this allows one more click to be made after infi-blocking the user to wipe out their created pages all at once. There are also lists of known spammer IP's; perhaps I should be looking into automating the task of adding these to blocklists, which currently operate per-wiki with no sitewide blocks here? --Carlb (talk) 20:25, 18 August 2011 (UTC)
Spambot attack

I noticed the captcha when I edited yesterday in Çciclopédia under IP, though the vandalism are made under false accounts of users. This confirms my suspicions about spambots analyzing these issues and the standard used in previous attacks.


  • (Deletion log); 04:07 . . Rhubella Marie (Talk | contribs) deleted "Order amoxicillin 500mg, 250mg, 650mg, 1000mg online - buy amoxicillin 1000mg - amoxicillin and abnormal menstual cycles" (Spam: content was: '...' (and the only contributor was '[[Special:Contributions/Paindweller1988|Paindweller19)
  • (Deletion log); 04:06 . . Rhubella Marie (Talk | contribs) deleted "Buy lithium 450mg, 300mg, 400mg cheap - lithium is used in - lithium volt gm" (Spam: content was: '...' (and the only contributor was '[[Special:Contributions/Schneider1961|Schneider19)
  • (Deletion log); 04:05 . . Rhubella Marie (Talk | contribs) deleted "Generic asacol 800mg, 400mg cheap - order asacol 400mg without prescription - asacol 800mg purchase" (Spam: content was: '...' (and the only contributor was '[[Special:Contributions/Boril1962|Boril19)
  • (Deletion log); 04:04 . . Rhubella Marie (Talk | contribs) deleted "Buy dostinex 0.25mg, 0.5mg, 1mg online - cheap generic dostinex - order dostinex 0.5mg generic online" (Spam: content was: '...' (and the only contributor was '[[Special:Contributions/Paindweller1988|Paindweller19)
  • (Deletion log); 04:03 . . Rhubella Marie (Talk | contribs) deleted "Order serevent 25mcg, 120doses online - buy generic serevent - buy serevent 120doses non prescription" (Spam: content was: '...' (and the only contributor was '[[Special:Contributions/Schneider1961|Schneider19)
  • (Deletion log); 04:03 . . Rhubella Marie (Talk | contribs) deleted "Buy atenolol 100mg, 50mg online - atenolol sore throat - purchase generic atenolol 50mg online" (Spam: content was: '...' (and the only contributor was '[[Special:Contributions/Paindweller1988|Paindweller19)

I request the checkuser tool in UnCommons to perform accurately in these cases the blocking IP's if there is much variation. Rhubella beach.jpgRhubella Marie, the rat sockpreppie 2,347 preppieditsRhubella.jpg 21:27, 18 August 2011 (UTC)

Check results[edit]

  • Aulbine1978 (Conversa | contribucións | bloquear) (Comprobar) (21:49, 17 de agosto de 2011 -- 09:38, 18 de agosto de 2011) [2]

(Bloqueado)

  1. 95.28.40.125
Preliminary checks
  • Boril1962
  • 46.73.214.39 (bloquear) (13:22, 17 de agosto de 2011) [1] (~8 de todos os usuarios)

[RDNS · RBLs · Traceroute · Geolocate · Tor check · WHOIS]

  • 46.73.178.208 (bloquear) (18:55, 10 de agosto de 2011) [1] (~3 de todos os usuarios)

[RDNS · RBLs · Traceroute · Geolocate · Tor check · WHOIS]

Check IP 46.73.214.39
  1. Schneider1961 (Conversa | contribucións | bloquear) (Comprobar) (22:33, 15 de agosto de 2011 -- 19:37, 17 de agosto de 2011) [3]

(Bloqueado)

1. 46.73.214.39

  1. Paindweller1988 (Conversa | contribucións | bloquear) (Comprobar) (22:08, 15 de agosto de 2011 -- 19:30, 17 de agosto de 2011) [4]

(Bloqueado)

1. 46.73.214.39

  1. Boril1962 (Conversa | contribucións | bloquear) (Comprobar) (13:22, 17 de agosto de 2011) [1]

(Bloqueado)

1. 46.73.214.39

Check IP 46.73.178.208
  1. Jody60 (Conversa | contribucións | bloquear) (Comprobar) (18:41, 10 de agosto de 2011 -- 06:23, 11 de agosto de 2011) [2]

(Bloqueado)

1. 46.73.178.208

  1. Boril1962 (Conversa | contribucións | bloquear) (Comprobar) (18:55, 10 de agosto de 2011) [1]

(Bloqueado)

1. 46.73.178.208

I think the result of the analysis of IP's has proved the existence of spambot. While analyzing best when each account was created seems to be of service attack multiple socks. Another interesting thing about all the IP's pointing to Moscow. Rhubella beach.jpgRhubella Marie, the rat sockpreppie 2,347 preppieditsRhubella.jpg 17:09, 19 August 2011 (UTC)

I had checked some IPs on mapt.be and I found there were addresses pointing at Moscow, Beijing and California. There are different sources for the spam | CartoonistHenning (talk) 22:38, 19 August 2011 (UTC)
This can accurately determine a rangeblock? Rhubella beach.jpgRhubella Marie, the rat sockpreppie 2,347 preppieditsRhubella.jpg 04:06, 20 August 2011 (UTC)