| |
Grawp has his way with SlimVirgin, (or at least her page about Poetlister) |
|
|
| Castle Rock |
Wed 17th September 2008, 6:28am
|
Senior Member
   
Group: Regulars
Posts: 358
Joined: Thu 13th Sep 2007, 7:27am
From: Oregon
Member No.: 3,051

|
QUOTE(Alison @ Tue 16th September 2008, 9:35pm)  Speaking of Grawp, he and his buds really hammered Werdna's wiki tonight. They've pretty-much trashed the place  It's like leaving your back door open when you're away and having a troupe of howler monkeys come visit. Basically, he's de-sysopped everyone, gained global steward rights, checkusered everyone (got my IP address, dammit. Ah well, here's another) and has free rein of the place. Werdna's going to have to shell in, lock the db and do a restore. It looks like Werdna had a separate wiki attached to it and had left default accounts wide-open allowing steward access to anyone. Grawp logs in and pwns it. Simultaneously impressive and a frickin' nuisance. I'd just cleaned up the earlier mess - ah, well Hey Castle Rock, how was it for you?  (User rights log); 04:12 . . Castle Rock (Talk | contribs) changed group membership for User:Alison from abusefilter and Sysops to (none) (You're not the boss of me now) QUOTE(jch @ Tue 16th September 2008, 11:12pm)  While mild lulz, what's "epic" about taking over a completely unprotected wiki?
It's like all the gripes people put on wikipedia about "omg someone haked ur sight, they edited an article!"
Because it was the Wiki dedicated to pioneering anti-Grawp systems.
|
|
|
|
|
|
| Alison |
Wed 17th September 2008, 6:56am
|

Skinny Cow!
       
Group: Regulars
Posts: 2,514
Joined: Tue 26th Jun 2007, 8:08pm
From: Kalifornia
Member No.: 1,806

|
QUOTE(Castle Rock @ Tue 16th September 2008, 11:28pm)  QUOTE(Alison @ Tue 16th September 2008, 9:35pm)  Speaking of Grawp, he and his buds really hammered Werdna's wiki tonight. They've pretty-much trashed the place  It's like leaving your back door open when you're away and having a troupe of howler monkeys come visit. Basically, he's de-sysopped everyone, gained global steward rights, checkusered everyone (got my IP address, dammit. Ah well, here's another) and has free rein of the place. Werdna's going to have to shell in, lock the db and do a restore. It looks like Werdna had a separate wiki attached to it and had left default accounts wide-open allowing steward access to anyone. Grawp logs in and pwns it. Simultaneously impressive and a frickin' nuisance. I'd just cleaned up the earlier mess - ah, well Hey Castle Rock, how was it for you?  (User rights log); 04:12 . . Castle Rock (Talk | contribs) changed group membership for User:Alison from abusefilter and Sysops to (none) (You're not the boss of me now) Dammit - pwnt  Alison de-sysop'd by Lateral. I'm guessing that will be all over ED by the morning. QUOTE(Castle Rock @ Tue 16th September 2008, 11:28pm)  QUOTE(jch @ Tue 16th September 2008, 11:12pm)  While mild lulz, what's "epic" about taking over a completely unprotected wiki?
It's like all the gripes people put on wikipedia about "omg someone haked ur sight, they edited an article!"
Because it was the Wiki dedicated to pioneering anti-Grawp systems. Thing is, it's just a scratch wiki. Lather - rinse - repeat. It's not like any damage to anything has been done. If Werdna configs things properly next time, it should be reasonably secure, etc. Then, visits from Grawp, etc would actually be to his advantage, honeypot-style. I think the problem was that Werdna installed the two wikis out of the box, linked them but never locked one of them down.
|
|
|
|
|
|
| Werdna648 |
Wed 17th September 2008, 8:26am
|
Neophyte
Group: Contributors
Posts: 13
Joined: Wed 5th Apr 2006, 10:03pm
Member No.: 101
WP user page -
talk
check -
contribs

|
QUOTE(Alison @ Wed 17th September 2008, 5:56pm)  Thing is, it's just a scratch wiki. Lather - rinse - repeat. It's not like any damage to anything has been done. If Werdna configs things properly next time, it should be reasonably secure, etc. Then, visits from Grawp, etc would actually be to his advantage, honeypot-style. I think the problem was that Werdna installed the two wikis out of the box, linked them but never locked one of them down.
Just a pesky combination of a MediaWiki bug amplified by PHP sucking, and a minor misconfiguration on my end, meaning that one of my wikis had Special:Userrights available to everyone. Oops. I've cleaned it all up, though. Only damage was on a 1-year-old wiki that I don't care about, and a 1-month-old wiki that I also don't care about. There were plenty of good things that he should really have done instead on the two private wikis there.
|
|
|
|
|
|
| Alison |
Wed 17th September 2008, 8:37am
|

Skinny Cow!
       
Group: Regulars
Posts: 2,514
Joined: Tue 26th Jun 2007, 8:08pm
From: Kalifornia
Member No.: 1,806

|
QUOTE(Werdna648 @ Wed 17th September 2008, 1:26am)  QUOTE(Alison @ Wed 17th September 2008, 5:56pm)  Thing is, it's just a scratch wiki. Lather - rinse - repeat. It's not like any damage to anything has been done. If Werdna configs things properly next time, it should be reasonably secure, etc. Then, visits from Grawp, etc would actually be to his advantage, honeypot-style. I think the problem was that Werdna installed the two wikis out of the box, linked them but never locked one of them down.
Just a pesky combination of a MediaWiki bug amplified by PHP sucking, and a minor misconfiguration on my end, meaning that one of my wikis had Special:Userrights available to everyone. Oops. I've cleaned it all up, though. Only damage was on a 1-year-old wiki that I don't care about, and a 1-month-old wiki that I also don't care about. There were plenty of good things that he should really have done instead on the two private wikis there. Shush now!  Don't give him ideas. I suggest also that you switch off anon editing for now and enable authenticated account creation only. Lather. Rinse. Repeat.
|
|
|
|
|
|
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:
| |