Last modified: 2011-12-24 22:48:39 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T17545, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 15545 - AntiSpoof should check against CentralAuth database
AntiSpoof should check against CentralAuth database
Status: RESOLVED DUPLICATE of bug 28747
Product: MediaWiki extensions
Classification: Unclassified
AntiSpoof (Other open bugs)
unspecified
All All
: Low enhancement (vote)
: ---
Assigned To: Nobody - You can work on this!
:
: 15841 19869 (view as bug list)
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2008-09-10 05:26 UTC by od_mishehu
Modified: 2011-12-24 22:48 UTC (History)
2 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description od_mishehu 2008-09-10 05:26:03 UTC
Currently, there is a MAJOR leak in the anti spoof system. In order to create an account name similar to that of an existing user (even if the user already has an SUL, which they probably mostly do), all you need to do is find a Wiki project where the user doesn't have an account yet (probably easy to guess, or else it can be checked), create a similar account name (this is an SUL), and then log in where the active user is active - and you have spoofed him successfully.
Comment 1 X! 2008-09-13 05:44:54 UTC
Changing to MediaWiki extensions, as AntiSpoof is an extension
Comment 2 X! 2008-10-19 18:47:55 UTC
*** Bug 15841 has been marked as a duplicate of this bug. ***
Comment 3 Mike.lifeguard 2009-06-18 02:51:59 UTC
Updated summary.
Comment 4 Chad H. 2009-07-22 22:39:56 UTC
*** Bug 19869 has been marked as a duplicate of this bug. ***
Comment 5 Sam Reed (reedy) 2011-12-24 22:48:39 UTC
Duping against bug 28747 as that's where the work has been done

*** This bug has been marked as a duplicate of bug 28747 ***

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links