Last modified: 2011-12-24 22:48:39 UTC

Wikimedia Bugzilla is closed!

Wikimedia has migrated from Bugzilla to Phabricator. Bug reports should be created and updated in Wikimedia Phabricator instead. Please create an account in Phabricator and add your Bugzilla email address to it.
Wikimedia Bugzilla is read-only. If you try to edit or create any bug report in Bugzilla you will be shown an intentional error message.
In order to access the Phabricator task corresponding to a Bugzilla report, just remove "static-" from its URL.
You could still run searches in Bugzilla or access your list of votes but bug reports will obviously not be up-to-date in Bugzilla.
Bug 15545 - AntiSpoof should check against CentralAuth database
AntiSpoof should check against CentralAuth database
Status: RESOLVED DUPLICATE of bug 28747
Product: MediaWiki extensions
Classification: Unclassified
AntiSpoof (Other open bugs)
All All
: Low enhancement (vote)
: ---
Assigned To: Nobody - You can work on this!
: 15841 19869 (view as bug list)
Depends on:
  Show dependency treegraph
Reported: 2008-09-10 05:26 UTC by od_mishehu
Modified: 2011-12-24 22:48 UTC (History)
2 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Description od_mishehu 2008-09-10 05:26:03 UTC
Currently, there is a MAJOR leak in the anti spoof system. In order to create an account name similar to that of an existing user (even if the user already has an SUL, which they probably mostly do), all you need to do is find a Wiki project where the user doesn't have an account yet (probably easy to guess, or else it can be checked), create a similar account name (this is an SUL), and then log in where the active user is active - and you have spoofed him successfully.
Comment 1 X! 2008-09-13 05:44:54 UTC
Changing to MediaWiki extensions, as AntiSpoof is an extension
Comment 2 X! 2008-10-19 18:47:55 UTC
*** Bug 15841 has been marked as a duplicate of this bug. ***
Comment 3 Mike.lifeguard 2009-06-18 02:51:59 UTC
Updated summary.
Comment 4 Chad H. 2009-07-22 22:39:56 UTC
*** Bug 19869 has been marked as a duplicate of this bug. ***
Comment 5 Sam Reed (reedy) 2011-12-24 22:48:39 UTC
Duping against bug 28747 as that's where the work has been done

*** This bug has been marked as a duplicate of bug 28747 ***

Note You need to log in before you can comment on or make changes to this bug.