From: Gavin Sinclair Date: 2004-09-28T23:02:03+09:00 Subject: Re: RubyGarden Spam On Tuesday, September 28, 2004, 11:49:00 PM, Curt wrote: > Gavin Sinclair wrote: >> >> On Tuesday, September 28, 2004, 10:53:17 PM, Curt wrote: >> >> > Curt Hibbs [mailto:curt@hibbs.com] >> >> >> >> Austin Zeigler is adding authentication to Ruwiki, and Tom >> >> Copeland is going >> >> to tie that into the RubyForge. So once all this is in place, >> the default >> >> RubyForge wiki will be Ruwiki and a single login to RubyForge >> will suffice >> >> for all normal RubyForge activities *as well as* all RubyForge >> >> hosted wikis. >> >> >> >> This will help, but obviously won't be the final answer. At >> least we will >> >> have a wiki written in Ruby, maintained by someone in our own >> community, >> >> where we can react intelligently to the ever-changing spam threats. >> >> > I forgot to mention... On one of my RubyForge wikis, the home >> page had been >> > spammed so many times that the original content had rolled off >> the version >> > history and I was unable to recover it. This is why I started >> checking for >> > spam every day. It is a royal pain-in-the-butt and I can't wait >> until I no >> > longer have to do this. >> >> See Jim's patch for UseModWiki at http://onestepback.org. He's >> actually done something about Wiki spam. Is that a record? > I sent that patch to Tom Copeland yesterday. He's looking into incorporating > that into the existing RubyForge wiki's to give us some relief until Austin > has Ruwiki authentication finished. As Mr. Burns would say, "Ex-cell-ent". I suspect that particular patch will be insufficient against sustained attacks, because some of them will be deemed acceptable, because they will use "HTTP" instead of "http". Still, it's a start, and one that can be tailored. Cheers, Gavin