machineagency / jubilee

jubilee source files; for the docs, see:
https://jubilee3d.com
Other
556 stars 113 forks source link

Possible security breach on Jubilee wiki site #139

Closed mhipszki closed 3 years ago

mhipszki commented 3 years ago

There seem to be unwanted changes on the Jubilee wiki looking at the change log:

Screenshot 2020-12-14 at 10 41 20

The Main page content also looks weird...

This is a fantastic project and thought it'd be useful to flag that @Poofjunior πŸ™‚

HaythamB commented 3 years ago

Yup looks like its been hacked. I'll see if I can disable new users for the time being until Joshua is on US daytime!

HaythamB commented 3 years ago

@Poofjunior I think you'll need to install https://www.mediawiki.org/wiki/Extension:UserMerge

I'm deleting all the spam pages, already restored the wiki contents page-by-page to remove all the bots' updates.

HaythamB commented 3 years ago

And looks like we started getting spam users as far back as Nov 22.

HaythamB commented 3 years ago

2549 pages deleted so far..

mhipszki commented 3 years ago

😱 omg

Prexsys-Beach commented 3 years ago

Why can’t we have nice things? :)

On Mon, Dec 14, 2020 at 6:32 AM Marton Hipszki notifications@github.com wrote:

😱 omg

β€” You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/machineagency/jubilee/issues/139#issuecomment-744408612, or unsubscribe https://github.com/notifications/unsubscribe-auth/AB5NPVMX5QFH54FT22VX6YLSUYAUZANCNFSM4U2RP2EA .

Poofjunior commented 3 years ago

Oof; thanks for bringing this up @mhipszki , and thanks for axing the spam pages @HaythamB . I only noticed the front page last night and promptly changed it back and blocked the user.

Yeah; it looks like we've hit a critical mass where we might have to add some flavor of captcha to keep the spam at bay longer term.

HaythamB commented 3 years ago

Ready to be marked as done, and I've created a relevant issue for addressing this in the longer term #141

Poofjunior commented 3 years ago

Thanks a bunch @HaythamB !