Vandalbot - Meta-Wiki (original) (raw)

From Meta, a Wikimedia project coordination wiki

This page in a nutshell: If you see a vandalbot, contact an administrator or a steward at your earliest opportunity to have them block the account or accounts involved. Do not panic, but act quickly. Remember, vandalbots are prohibited!

A vandalbot is a script which automatically performs some kind of malicious edit or similar operation to a wiki at high rate. When you see one, you have to know what to do. Read this page now. Don't leave it until the heat is on!

For Wikimedians who are not administrators, vandalbots can be reported at vandalism reports.

Operating vandalbots on any Wikimedia Foundation project is prohibited (see the relevant section of the Terms of Use for details).

A spambot is, like a vandalbot, an automated process (bot) that will vandalize a wiki by adding spam to the wiki pages or creating a mass of spam pages. They can be dealt with in the same way as vandalbots, so continue reading.

The basic response to a vandalbot is to first block the account and revert its actions using rollback. You can revert edits without the rollback right, but that's slow and tedious. You're better off finding an administrator. If there are no administrators around, the stewards will be able to assist you. You may find a full list of stewards here. You can also contact a global rollbacker if you don't have rollback rights.

If you are an administrator and you see a vandalbot that is editing existing pages, you're encouraged to do the following:

  1. Block it. Make sure to enable autoblock and to block account creations.
  2. Go to the vandalbot's contributions page.
  3. Append ?bot=1 to the end of the contributions page URL of the vandalbot and load that page. For example: https://meta.wikimedia.org/wiki/Special:Contributions/Example?bot=1.
    This will hide the bot's edits and your rollbacks from the recent changes page.
  4. Click on all the rollback links.
  5. Please contact a steward to globally lock the account and/or globally block the IP address. Please post on Steward requests/Global under the relevant section.
  6. Additionally, please consider asking for global URL blacklisting.

If there is no administrator available, or it is an emergency or crosswiki attack, the Wikimedia stewards are there to help you. You may quickly contact them on the #wikimedia-stewardsconnect IRC channel or by posting a message in the vandalism reports board. Stewards have complete access to the wiki interface and functions in all Wikimedia projects as well to powerful global tools which can be used in order to stop the attack.

It is always helpful to notify stewards at the vandalism reports board for these cases, even if you have local administrator assistance, so they can have a look at the issue and take other measures, such as locking the malicious accounts involved.