Vandalbot
What is a vandalbot?
[edit]A vandalbot is a script which automatically performs some kind of malicious edit or similar operation to a wiki at high rate. When you see one, you have to know what to do. Read this page now. Don't leave it until the heat is on!
For Wikimedians who are not administrators, vandalbots can be reported at vandalism reports.
Operating vandalbots on any Wikimedia Foundation project is prohibited (see the relevant section of the Terms of Use for details).
Spambots
[edit]A spambot is, like a vandalbot, an automated process (bot) that will vandalize a wiki by adding spam to the wiki pages or creating a mass of spam pages. They can be dealt with in the same way as vandalbots, so continue reading.
Response from administrators
[edit]The basic response to a vandalbot is to first block the account and revert its actions using rollback. You can revert edits without the rollback right, but that's slow and tedious. You're better off finding an administrator. If there are no administrators around, the stewards will be able to assist you. You may find a full list of stewards here. You can also contact a global rollbacker if you don't have rollback rights.
If you are an administrator and you see a vandalbot that is editing existing pages, you're encouraged to do the following:
- Block it. Make sure to enable autoblock and to block account creations.
- Go to the vandalbot's contributions page.
- Append
?bot=1
to the end of the contributions page URL of the vandalbot and load that page. For example:https://meta.wikimedia.org/wiki/Special:Contributions/Example?bot=1
.
This will hide the bot's edits and your rollbacks from the recent changes page. - Click on all the rollback links.
- Please contact a steward to globally lock the account and/or globally block the IP address. Please post on Steward requests/Global under the relevant section.
- Additionally, please consider asking for global URL blacklisting.
- A tip: Note that it will be easier to click on all the rollback links if you open them all in a new tab.
- If the vandalbot has also created a mass of pages those can be bulk deleted, usually by any administrator, by accessing the page Special:Nuke and following the instructions. Be careful to enter the correct username in the form!
- It may also be useful to bring the incident to the attention of the community so that others can be on the lookout for similar attacks soon after.
Steward response
[edit]If there is no administrator available, or it is an emergency or crosswiki attack, the Wikimedia stewards are there to help you. You may quickly contact them on the #wikimedia-stewardsconnect IRC channel or by posting a message in the vandalism reports board. Stewards have complete access to the wiki interface and functions in all Wikimedia projects as well to powerful global tools which can be used in order to stop the attack.
It is always helpful to notify stewards at the vandalism reports board for these cases, even if you have local administrator assistance, so they can have a look at the issue and take other measures, such as locking the malicious accounts involved.
Tools
[edit]- Extension:AbuseFilter is a tool available at all Wikimedia wikis at "Special:AbuseFilter", which applies heuristics to actions by users, such as edits, based on filters that can be configured locally to prevent various kinds of vandalism. The configuration of the filters is not easy so if you have not used the tool ask first or you may end blocking legitimate edits.
- Extension:SpamBlacklist is a tool that will block from saving pages containing a certain URL. A local spam blacklist exists on each wiki at "MediaWiki:Spam-blacklist" with a global one working for all projects located at spam blacklist. Do not use SpamBlacklist or AbuseFilter without a basic understanding of regular expressions.
- CheckUser is a tool available for users with the
checkuser
permission which is to be used to fight vandalism and prevent abuse to the projects. Due to the sensitive nature of the tool, it is only used as a last resort for difficult cases.