[SAC] Trac Spam

Folks,

The Trac Spammers have found our Trac instances and are actively spamming
those that allow anonymous ticket creation and modification. For example
this recent spam on the Mapbender trac instance:

Changes (by anonymous):

  * cc: mapbender_dev@lists.osgeo.org (removed)
  * cc: None (added)
   * component: core => print
   * summary: Titled GUIs (new zebra) => None
   * version: 2.4.1 => 2.1
   * milestone: => Support usage of Styled Layer Descriptors (SLD)
   * keywords: login, gui list => None

Comment:

  {{{
  #!html
  <u style="display:none"><a href=http://search-
  painter.bravehost.com/map.html>Painter</a> <a href=http://the-interior-
  design.bravehost.com/map.html>Interior design</a></u>
  }}}

Beyond the fact that our google karma is being redirected to serve
nefarious ends, there is also random damage being done to legitimate
trac tickets.

For the time being I have disabled anonymous ticket creation and
modification. Anyone wanting to submit or modify a ticket will now
need to login with an OSGeo userid. If this is contrary to the wishes
of the Mapbender PSC I (or Astrid or Christoph) can revert this change.

Best regards,
--
---------------------------------------+--------------------------------------
I set the clouds in motion - turn up | Frank Warmerdam, warmerdam@pobox.com
light and sound - activate the windows | http://pobox.com/~warmerdam
and watch the world go round - Rush | President OSGeo, http://osgeo.org

On Fri, July 6, 2007 16:49, Frank Warmerdam wrote:

Folks,

The Trac Spammers have found our Trac instances and are actively spamming
those that allow anonymous ticket creation and modification. For example
this recent spam on the Mapbender trac instance:

Changes (by anonymous):

  * cc: mapbender_dev@lists.osgeo.org (removed)
  * cc: None (added)
   * component: core => print
   * summary: Titled GUIs (new zebra) => None
   * version: 2.4.1 => 2.1
   * milestone: => Support usage of Styled Layer Descriptors (SLD)
   * keywords: login, gui list => None

Comment:

  {{{
  #!html
  <u style="display:none"><a href=http://search-
  painter.bravehost.com/map.html>Painter</a> <a href=http://the-interior-
  design.bravehost.com/map.html>Interior design</a></u>
  }}}

Beyond the fact that our google karma is being redirected to serve
nefarious ends, there is also random damage being done to legitimate
trac tickets.

For the time being I have disabled anonymous ticket creation and
modification. Anyone wanting to submit or modify a ticket will now
need to login with an OSGeo userid. If this is contrary to the wishes
of the Mapbender PSC I (or Astrid or Christoph) can revert this change.

Best regards,

This is probably the best solution, thank you for making these changes. We
will launch some information to this regard to the Mapbender users.

Bets regards,

--
Arnulf Benno Christl
http://www.osgeo.org
(OSGeo Board Member)
+50.7342N +7.0707E