The Wikipedia Review: A forum for discussion and criticism of Wikipedia
Wikipedia Review Op-Ed Pages

Welcome, Guest! ( Log In | Register )

2 Pages V < 1 2  
Reply to this topicStart new topic
> Grawp has his way with SlimVirgin, (or at least her page about Poetlister)
Castle Rock
post Wed 17th September 2008, 6:28am
Post #21


Senior Member
****

Group: Regulars
Posts: 358
Joined: Thu 13th Sep 2007, 7:27am
From: Oregon
Member No.: 3,051



QUOTE(Alison @ Tue 16th September 2008, 9:35pm) *

Speaking of Grawp, he and his buds really hammered Werdna's wiki tonight.

They've pretty-much trashed the place ohmy.gif It's like leaving your back door open when you're away and having a troupe of howler monkeys come visit.

Basically, he's de-sysopped everyone, gained global steward rights, checkusered everyone (got my IP address, dammit. Ah well, here's another) and has free rein of the place. Werdna's going to have to shell in, lock the db and do a restore.

It looks like Werdna had a separate wiki attached to it and had left default accounts wide-open allowing steward access to anyone. Grawp logs in and pwns it. Simultaneously impressive and a frickin' nuisance. I'd just cleaned up the earlier mess - ah, well dry.gif

Hey Castle Rock, how was it for you? huh.gif tongue.gif laugh.gif


laugh.gif
(User rights log); 04:12 . . Castle Rock (Talk | contribs) changed group membership for User:Alison from abusefilter and Sysops to (none) (You're not the boss of me now)

QUOTE(jch @ Tue 16th September 2008, 11:12pm) *

While mild lulz, what's "epic" about taking over a completely unprotected wiki?

It's like all the gripes people put on wikipedia about "omg someone haked ur sight, they edited an article!"


Because it was the Wiki dedicated to pioneering anti-Grawp systems.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
The Joy
post Wed 17th September 2008, 6:32am
Post #22


I am a millipede! I am amazing!
********

Group: Regulars
Posts: 3,820
Joined: Sat 17th Feb 2007, 2:25am
From: The Moon
Member No.: 982



I hate to ask this, but has Wikia fallen to Grawp or do their devs actually have a strong defense system?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Alison
post Wed 17th September 2008, 6:56am
Post #23


Skinny Cow!
********

Group: Regulars
Posts: 2,514
Joined: Tue 26th Jun 2007, 8:08pm
From: Kalifornia
Member No.: 1,806



QUOTE(Castle Rock @ Tue 16th September 2008, 11:28pm) *

QUOTE(Alison @ Tue 16th September 2008, 9:35pm) *

Speaking of Grawp, he and his buds really hammered Werdna's wiki tonight.

They've pretty-much trashed the place ohmy.gif It's like leaving your back door open when you're away and having a troupe of howler monkeys come visit.

Basically, he's de-sysopped everyone, gained global steward rights, checkusered everyone (got my IP address, dammit. Ah well, here's another) and has free rein of the place. Werdna's going to have to shell in, lock the db and do a restore.

It looks like Werdna had a separate wiki attached to it and had left default accounts wide-open allowing steward access to anyone. Grawp logs in and pwns it. Simultaneously impressive and a frickin' nuisance. I'd just cleaned up the earlier mess - ah, well dry.gif

Hey Castle Rock, how was it for you? huh.gif tongue.gif laugh.gif


laugh.gif
(User rights log); 04:12 . . Castle Rock (Talk | contribs) changed group membership for User:Alison from abusefilter and Sysops to (none) (You're not the boss of me now)

Dammit - pwnt tongue.gif Alison de-sysop'd by Lateral. I'm guessing that will be all over ED by the morning.
QUOTE(Castle Rock @ Tue 16th September 2008, 11:28pm) *

QUOTE(jch @ Tue 16th September 2008, 11:12pm) *

While mild lulz, what's "epic" about taking over a completely unprotected wiki?

It's like all the gripes people put on wikipedia about "omg someone haked ur sight, they edited an article!"

Because it was the Wiki dedicated to pioneering anti-Grawp systems.

Thing is, it's just a scratch wiki. Lather - rinse - repeat. It's not like any damage to anything has been done. If Werdna configs things properly next time, it should be reasonably secure, etc. Then, visits from Grawp, etc would actually be to his advantage, honeypot-style. I think the problem was that Werdna installed the two wikis out of the box, linked them but never locked one of them down.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Werdna648
post Wed 17th September 2008, 8:26am
Post #24


Neophyte


Group: Contributors
Posts: 13
Joined: Wed 5th Apr 2006, 10:03pm
Member No.: 101

WP user page - talk
check - contribs



QUOTE(Alison @ Wed 17th September 2008, 5:56pm) *

Thing is, it's just a scratch wiki. Lather - rinse - repeat. It's not like any damage to anything has been done. If Werdna configs things properly next time, it should be reasonably secure, etc. Then, visits from Grawp, etc would actually be to his advantage, honeypot-style. I think the problem was that Werdna installed the two wikis out of the box, linked them but never locked one of them down.


Just a pesky combination of a MediaWiki bug amplified by PHP sucking, and a minor misconfiguration on my end, meaning that one of my wikis had Special:Userrights available to everyone. Oops. I've cleaned it all up, though. Only damage was on a 1-year-old wiki that I don't care about, and a 1-month-old wiki that I also don't care about. There were plenty of good things that he should really have done instead on the two private wikis there.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Alison
post Wed 17th September 2008, 8:37am
Post #25


Skinny Cow!
********

Group: Regulars
Posts: 2,514
Joined: Tue 26th Jun 2007, 8:08pm
From: Kalifornia
Member No.: 1,806



QUOTE(Werdna648 @ Wed 17th September 2008, 1:26am) *

QUOTE(Alison @ Wed 17th September 2008, 5:56pm) *

Thing is, it's just a scratch wiki. Lather - rinse - repeat. It's not like any damage to anything has been done. If Werdna configs things properly next time, it should be reasonably secure, etc. Then, visits from Grawp, etc would actually be to his advantage, honeypot-style. I think the problem was that Werdna installed the two wikis out of the box, linked them but never locked one of them down.


Just a pesky combination of a MediaWiki bug amplified by PHP sucking, and a minor misconfiguration on my end, meaning that one of my wikis had Special:Userrights available to everyone. Oops. I've cleaned it all up, though. Only damage was on a 1-year-old wiki that I don't care about, and a 1-month-old wiki that I also don't care about. There were plenty of good things that he should really have done instead on the two private wikis there.

Shush now! wink.gif Don't give him ideas.

I suggest also that you switch off anon editing for now and enable authenticated account creation only.

Lather. Rinse. Repeat.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Milton Roe
post Wed 17th September 2008, 4:01pm
Post #26


Known alias of J. Random Troll
*********

Group: Regulars
Posts: 10,209
Joined: Thu 28th Feb 2008, 1:03am
Member No.: 5,156

WP user page - talk
check - contribs



QUOTE(Alison @ Wed 17th September 2008, 1:37am) *

I suggest also that you switch off anon editing for now and enable authenticated account creation only.

Lather. Rinse. Repeat.

Say, and that might work for Wikipedia, too! blink.gif rolleyes.gif ohmy.gif laugh.gif

Flash moment of stark insight. ph34r.gif wacko.gif

wink.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Anonymous editor
post Thu 18th September 2008, 12:33am
Post #27


Über Member
*****

Group: Regulars
Posts: 666
Joined: Mon 4th Aug 2008, 6:21pm
Member No.: 7,398



pretty pathetic. ByAppointmentTo and Grawp. Congrats, you hacked a wiki that no one cares about. Go blow each other to celebrate. These beings are wasting oxygen.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

2 Pages V < 1 2
Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

-   Lo-Fi Version Time is now: 21st 5 13, 2:09pm