Page MenuHomePhabricator

spammers putting lots of blank lines at the top
Closed, InvalidPublic

Description

Author: bob9

Description:
I'v seen plenty of wiki spam that uses the 1px trick to make spam links that can
be seen in the source of the webpage but arn't visible. Today I saw somthing new.

A spammer made a new page on the wiki. SPam links can be seen with view source
on the page
but don't show when edit is selected. The html looks like this.

</p>
<hr />
<p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />

</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />

</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />

</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p><p><br />
</p>
<div style="overflow: auto; height: 1px;">

<p><a href="http://spamspamspam/boards/board.cgi?user=phentermine"
class='external text'
title="http://spamspamspam/boards/board.cgi?user=phentermine" rel="nofollow">Buy
Phentermine</a>
<a href="http://spamspamspam/boards/board.cgi?user=buytramadol" class='external
text' title="http://spamspamspam/boards/board.cgi?user=buytramadol"
rel="nofollow">Buy Tramadol</a>
<a href="http://spamspamspam/boards/board.cgi?user=oxycontin" class='external
text' title="http://spamspamspam/boards/board.cgi?user=oxycontin"
rel="nofollow">Buy Oxycontin</a>
<a href="http://spamspamspam/cgi/gb.id?hydrocodoner" class='external text'
title="http://spamspamspam/cgi/gb.id?hydrocodoner" rel="nofollow">buy
hydrocodone</a>
</p>


Version: 1.5.x
Severity: minor
URL: http://ps.wikipedia.org/w/index.php?title=User_talk:66.130.209.171&curid=1736&diff=5443&oldid=4976

Details

Reference
bz4252

Event Timeline

bzimport raised the priority of this task from to Medium.Nov 21 2014, 8:59 PM
bzimport added a project: MediaWiki-Parser.
bzimport set Reference to bz4252.
bzimport added a subscriber: Unknown Object (MLST).

Please provide an URL to a page where we can see this.

Is it just a bunch of blank lines, and then the usual spam crap?

gangleri wrote:

Hi Brion!

Added an URL. Have seen dozens of these during the last days. The code from
comment 0 seems to be copied from View > Page Source in the browser.

What is new here (at this url) is that user talk pages of anonymous users are
spamed too. Normaly pages with same title in English (which occur in MediaWiki -
Language.php) are spamed.

Note about this summary:
"spamer creating spam links that don't show in edit"

*don't show in edit* is not a proper description. The spam shows only if you
scroll in the edit-texarea.

What could be done to overcome this trick? Maybe action=edit should jump to the
first nonempty line. If this is a solution please change the sumary of this bug.

best regards reinhardt [[user:Gangleri]]

P.S.
a) This is the only bug submitted by Bob using an [[en:Mailinator]] account. It
is speculative if he gets the feedback.
b) His MediaZilla account (both email address and name) can be hijacked. I think
that the domain mailinator.com should be blacklisted at MediaZilla.

gangleri wrote:

(In reply to comment #2)

What could be done to overcome this trick? Maybe action=edit should jump to the
first nonempty line. If this is a solution please change the sumary of this bug.

A better suggestion is:
Maybe action=edit should jump to the first *printable* character. There are lot
of scenarios where the first *nonempty* line contains whitespace or dieacritical
marks which do not display.

robchur wrote:

The spam blacklist or regexes would have caught this. It's not like we can fix
the issue with a polite email to the marketing department of lunchmeat.net.