























New user registration was stopped on June 11 and then re-enabled after the project added Anubis to try to foil the attacker's mass account registrations. That did not work, so registration was disabled again on June 12.
Before new user registration was disabled, the 'captcha' for making a new account would be a shell command that you would have to run and paste the output of. Typically involving running pacman, to prevent Ubuntu users from signing up. Indeed there is still a similar challenge on the new user registration for the ArchWiki, when I load the page it asks me to enter the output of LC_ALL=C pacman -V|sed -r "s#[0-9]+#$(date -u +%m)#g"|base32|head -1.
If the automated attacker has been programmed to run these scripts to sign up for an account, perhaps the sign-up page could serve the attackers a forkbomb to run, or get them to post to an Arch Linux URL to reveal their IP address...
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。