There was a bot spamming our trac. I can only assume it's still trying but I've 
stopped it for now. I've removed TICKET_APPEND and TICKET_CREATE_SIMPLE from 
the "authenticated" group in the trac admin. This means regular users won't be 
able to comment on or create new tickets.

Rudy Richter reports that the earliest spam ticket was #14656 and the last was 
#14814.

John Bailey suggests installing TracSpamFilter filter, limiting the number of 
tickets per hour (for the authenticated group, presumably), requiring email 
addresses and "I also tuned the spam filter to negatively score users who did 
not have a name or an email address on their account -- which would likely not 
be a good idea for you guys since you probably have about a billion users out 
there".

Happy Thanksgiving from the spammers, I guess!

-Colin

Reply via email to