Forum:Spam bots
The spam bot accounts are becoming a serious problem. Multiple accounts are created each day, editing their own user pages, creating spam pages, and also, for some reason, targeting specific pages like User:Atarax. Clearly, the current Captcha isn't working. How can we deal with this? Does anyone have access to the behind the scenes stuff? Do we need to contact wikkii? Can we try anything listed here?
--An Adventurer 01:58, 1 February 2012 (EST)
You read my mind, it really is getting ridiculous now lol. While I don't know anything about the behind the scenes stuff, I believe Atarax has been targeted because his name is actually a drug and I have seen it pop up in spam sometimes myself...perhaps he should change his name if nothing else works.
--Ash (Arkalor) 03:12, 1 February 2012 (EST)
Well ten hours later unfortunately the size of our database caused some issues with the db schema update and the new installation did not validate completely. So I reverted to the image from last night and I'm putting this on hold until I figure out a way around it. For the spamming what I've done in the interim (and what we may want to just stay with this as there aren't any real foolproof ways to prevent spam using filtering/regex/blacklists, especially for spammers that are at the keyboard and not just a bot script) is disable new account creation except for existing users. That is anyone wanting to create a new account will need to ask someone in game or on the turbine forums or via email to create an account for them.
Any user once logged in can go to Special:UserLogin and click on the "Create an account" link. Your username will appear but you just erase that and enter the name the person wants, make a temporary password, then give the password to the person wanting the account. Then the person can log in on the new account and change the password to one of their choice. This might discourage casual edits since there would be a delay between someone first wanting to change something and when they would be able to log in so it isn't ideal longterm. I'm thinking I might create a custom creation script that would ask questions that anyone that plays AC would know but a spambot wouldn't be able to easily guess (though it would still be vulnerable to a real person that could just google the answer I suppose).
I added a link to information to most of the places where someone can try to login/edit so they will know how to get an account (view source, login, create account).