Hi Kiran, 

Yes, my recommendation:

1. Jump into #asfinfra on freeonode, find Joe, or Gavin or Daniel,
ask for help. If you don't have IRC, email infrastruct...@apache.org
and/or file a https://issues.apache.org/jira/browse/INFRA ticket

2. Request that they enable ASAP ContributorsGroup only acls

I know that many Apache wikis (MoinMon) are being attackedÅ 

Cheers,
Chris


++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Chris Mattmann, Ph.D.
Senior Computer Scientist
NASA Jet Propulsion Laboratory Pasadena, CA 91109 USA
Office: 171-266B, Mailstop: 171-246
Email: chris.a.mattm...@nasa.gov
WWW:  http://sunset.usc.edu/~mattmann/
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Adjunct Assistant Professor, Computer Science Department
University of Southern California, Los Angeles, CA 90089 USA
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++




-----Original Message-----
From: kiran chitturi <chitturikira...@gmail.com>
Reply-To: "dev@nutch.apache.org" <dev@nutch.apache.org>
Date: Thursday, March 28, 2013 12:15 PM
To: "dev@nutch.apache.org" <dev@nutch.apache.org>
Subject: Fwd: Important : Bunch of Spam Created under Nutch Wiki!!

>Thanks to Ken (check message below) for reporting our insecure wiki. I
>have checked it and anyone can create an fake account and edit any of our
>wiki pages or create new ones.
>
>
>When I first registered to the wiki, all the pages are immutable and
>Lewis had to add me to Contributors group to make changes to the wiki.
>
>
>Probably, the setting was hacked for now and that is the reason we are
>facing lot of spam.
>
>
>Can we contact the infra@apache and request them to lock down the wiki as
>the other groups did ?
>
>
>
>
>---------- Forwarded message ----------
>From: Ken Krugler <kkrugler_li...@transpac.com>
>Date: Thu, Mar 28, 2013 at 1:35 PM
>Subject: Re: Important : Bunch of Spam Created under Nutch Wiki!!
>To: dev@nutch.apache.org
>
>
>Hi Kiran,
>
>On Mar 28, 2013, at 2:03am, kiran chitturi wrote:
>
>
>Thank you Ken for the information. I think the access is already
>restricted to Contributors Only. Someone can please confirm, if it is
>not. 
>
>
>
>
>
>It's not, as far as I know. I just created a fake account, logged in with
>it, and edited the front page.
>
>
>If anyone needs to edit wiki, they would need to ask someone to get
>access to wiki pages.
>
>
>Do you know if Solr still got hit by spam after locking down the wiki ?
>
>
>
>
>
>
>I think that change helped cut down most of the spam, but I don't monitor
>the Solr list that closely, sorry.
>
>
>-- Ken
>
>
>
>
>
>
>On Thu, Mar 28, 2013 at 1:40 AM, Ken Krugler
><kkrugler_li...@transpac.com> wrote:
>
>
>
>On Mar 27, 2013, at 6:54pm, kiran chitturi wrote:
>
>
>Thank you Binoy for reporting.
>
>
>We have been monitoring the pages and deleting them when we get time but
>there are more coming up. Today, I have seen a spam editing on the home
>page of Nutch wiki. It has inserted spam links under tutorials.
>
>
>We need to find a permanent solution to this. I wonder if any other
>list-servs are facing the same issue.
>
>
>
>
>
>
>Yes - Solr recently had to lock down editing on their wiki:
>
>
>
>The wiki at http://wiki.apache.org/solr/ has come under attack by
>spammers more frequently of late, so the PMC has decided to lock it down
> in an attempt to reduce the work involved in tracking and removing spam.
>
>From now on, only people who appear on
>http://wiki.apache.org/solr/ContributorsGroup will be able to
>create/modify/delete wiki pages.
>
>Please request either on the solr-u...@lucene.apache.org or on
>d...@lucene.apache.org to have your wiki username added to the
>ContributorsGroup
> page - this is a one-time step.
>
>
>
>
>So I think you need to make a request to Infra to lock down the wiki,
>then add people (generally in response to explicit requests) to the
>ContributorsGroup page.
>
>
>-- Ken
>
>
>
>
>
>
>On Thu, Mar 28, 2013 at 12:49 AM, Binoy d
><binoy...@gmail.com> wrote:
>
>I am quite suprised looking at the notification I am getting for new
>pages for Nutch Wiki
>Example :
>http://wiki.apache.org/nutch/KarlPuent
>
>I see at least 25-35 emails regarding such notification.
>
>All of the links I got are  rooted under
>http://wiki.apache.org/nutch/ <http://wiki.apache.org/nutch/>
>
>
>Is some one looking into this , If needed I can gladly forward emails to
>the person cleaning it up as I am not sure if every one has access to
>delete the pages.
>
>Regards,
>b
>
>---------- Forwarded message ----------
>From: Apache Wiki <wikidi...@apache.org>
>Date: Wed, Mar 27, 2013 at 9:32 PM
>Subject: [Nutch Wiki] Trivial Update of "EdwinaBro" by EdwinaBro
>To: Apache Wiki <wikidi...@apache.org>
>
>
>Dear Wiki user,
>
>You have subscribed to a wiki page or wiki category on "Nutch Wiki" for
>change notification.
>
>The "EdwinaBro" page has been changed by EdwinaBro:
>http://wiki.apache.org/nutch/EdwinaBro
>
>New page:
>I am 24 years old and my name is Edwina Brownlee. I life in Corjolens
>(Switzerland).<<BR>>
><<BR>>
><<BR>>
>Take a look at my web-site ... [[http://modform.org/SolomonKr|Continue
><http://modform.org/SolomonKr%7CContinue>]]
>
>
>
>
>
>
>
>
>
>-- 
>Kiran Chitturi
>
>
> <http://www.linkedin.com/in/kiranchitturi>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>--------------------------
>Ken Krugler
>+1 530-210-6378 <tel:%2B1%20530-210-6378>
>http://www.scaleunlimited.com <http://www.scaleunlimited.com/>
>custom big data solutions & training
>Hadoop, Cascading, Cassandra & Solr
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>-- 
>Kiran Chitturi
>
>
> <http://www.linkedin.com/in/kiranchitturi>
>
>
>
>
>
>
>
>
>
>
>
>
>--------------------------
>Ken Krugler
>+1 530-210-6378 <tel:%2B1%20530-210-6378>
>http://www.scaleunlimited.com
>custom big data solutions & training
>Hadoop, Cascading, Cassandra & Solr
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>
>-- 
>Kiran Chitturi
>
>
> <http://www.linkedin.com/in/kiranchitturi>
>
>
>
>
>
>
>
>
>

Reply via email to