[GRASS-dev] new trac anti-spam filter

FYI!

(I'm in the OSGeo-SAC team but thought to fwd here to avoid any bus factor)

Indeed, we have spam in our wiki, see
https://trac.osgeo.org/grass/admin/spamfilter/monitor

I cleaned that one up now.

Markus

---------- Forwarded message ----------
From: Sandro Santilli <strk@keybit.net>
Date: Sat, May 7, 2016 at 7:01 PM
Subject: Re: [SAC] fail2ban osgeo-trac-spam jail disabled
To: System Administration Committee Discussion/OSGeo <sac@lists.osgeo.org>

On Sat, May 07, 2016 at 04:40:16PM +0200, Markus Neteler wrote:

On May 7, 2016 3:57 PM, "Sandro Santilli" <strk@keybit.net> wrote:
...
> Contextually, I've made sure TracSpamPlugin is enabled in each
> and every instance, so from now on spam filtering should be dealth
> with via the admin panel of each instance.

Thanks. Is there any action item related to this for trac admins?

The action is: configure the filter.
Unfortunately the configuration is per-instance so cannot be shared.
I've been playing a bit with ossim as it was under attack.

The default configuration doesn't catch much spam, especially as
the score of being authenticated is very high (20). Not many systems
allow spammers to register accounts (fixing the LDAP registration
is top priority to reduce spam). The score of various filters can
be set via https://trac.osgeo.org/INSTANCE/admin/spamfilter/config

It also helped to create a BadContent wiki page, see
https://trac.osgeo.org/ossim/wiki/BadContent
It needs be improved, and ideally copied among the various
instances.

Then you can train the bayes db, going to:
https://trac.osgeo.org/INSTANCE/admin/spamfilter/monitor
and telling spam from ham.

These activities can by default only be done by those who
have TRAC_ADMIN permission, but the plugin adds also spamfilter
specific permissions you could use to grant more power to
others. Details here:
https://trac.edgewall.org/wiki/SpamFilter#Permissions

If someone would write these various things on a wiki page and link
the new page from Trac_Instances it would be helpful.

--strk;
_______________________________________________
Sac mailing list
Sac@lists.osgeo.org
http://lists.osgeo.org/mailman/listinfo/sac

On Sat, May 7, 2016 at 1:17 PM, Markus Neteler <neteler@osgeo.org> wrote:

FYI!

(I'm in the OSGeo-SAC team but thought to fwd here to avoid any bus factor)

Indeed, we have spam in our wiki, see
https://trac.osgeo.org/grass/admin/spamfilter/monitor

I cleaned that one up now.

Thanks Markus. The spam is pretty disrupting. We got more just few minutes
ago:

https://trac.osgeo.org/grass/timeline

On May 7, 2016 8:10 PM, “Vaclav Petras” <wenzeslaus@gmail.com> wrote:

Thanks Markus. The spam is pretty disrupting. We got more just few minutes ago:

https://trac.osgeo.org/grass/timeline

Cleaned and Bayes filter better trained now.

Markus

On Sat, May 7, 2016 at 7:19 PM, Markus Neteler <neteler@osgeo.org> wrote:

> https://trac.osgeo.org/grass/timeline
>

Cleaned and Bayes filter better trained now.

New spam wiki pages and they seems to contain text from:

https://trac.osgeo.org/grass/wiki/BadContent

On Tue, May 10, 2016 at 11:50 PM, Vaclav Petras <wenzeslaus@gmail.com> wrote:

On Sat, May 7, 2016 at 7:19 PM, Markus Neteler <neteler@osgeo.org> wrote:

> https://trac.osgeo.org/grass/timeline
>
Cleaned and Bayes filter better trained now.

New spam wiki pages and they seems to contain text from:

...

Solved by visiting (as admin)
https://trac.osgeo.org/grass/admin/spamfilter/monitor

and confirming the already caught pages as "spam". So the blacklist in
the "BadContent" pages worked ok but (at time?) the just still shows
up unless treated properly in the "monitoring" page. That's all I know
due to lack of time to study the trac spamfilter plugin properly...

But any use can report spam (I think there is a new link in the upper
right corner).

Markus

On Wed, May 11, 2016 at 10:00 AM, Markus Neteler <neteler@osgeo.org> wrote:

But any use can report spam (I think there is a new link in the upper
right corner).

Perhaps only admins. I don't see it.

https://trac.osgeo.org/grass/wiki/Call%20Canada%201855-800-8493%20pogo%20tech.h%20support%20Phone%20Number/791%20pogo%20phone%20number%20usa.?version=1
https://trac.osgeo.org/grass/wiki/Call%20Canada%201855-899-1836%20Mint%20tech%20support%20Phone%20Number/791%20pogo%20phone%20number%20usa.?version=1

2016-05-14 22:58 GMT+02:00 Vaclav Petras <wenzeslaus@gmail.com>:

But any use can report spam (I think there is a new link in the upper
right corner).

Perhaps only admins. I don't see it.

probably (I can see it). Ma

--
Martin Landa
http://geo.fsv.cvut.cz/gwiki/Landa
http://gismentors.cz/mentors/landa

On May 7, 2016 7:17 PM, “Markus Neteler” <neteler@osgeo.org> wrote:

FYI!

(I’m in the OSGeo-SAC team but thought to fwd here to avoid any bus factor)

Indeed, we have spam in our wiki, see
https://trac.osgeo.org/grass/admin/spamfilter/monitor

(above page is only visible to trac admins)

Update: meanwhile I can actively delete spam accounts in LDAP, the user registry.

Markus