Go to file
Chad Horohoe e3dcbf79e1 Swapping defaultbranch for trace
The former is a maintenance nightmare when branching.

Bug:T146293
Change-Id: I09f02c827c5d93d4540231173f3b7ecfbfd17808
2016-10-24 16:38:30 -07:00
api Remove pre-1.25 API compatibility code 2016-09-20 15:32:17 -04:00
i18n Localisation updates from https://translatewiki.net. 2016-10-24 22:49:32 +02:00
.gitignore composer test entry point 2015-11-23 22:00:42 +01:00
.gitreview Swapping defaultbranch for trace 2016-10-24 16:38:30 -07:00
BaseBlacklist.php Replace Revision::getText() 2016-10-05 00:33:30 +01:00
cleanup.php Replace Revision::getText() 2016-10-05 00:33:30 +01:00
composer.json build: Updating development dependencies 2016-01-05 10:40:48 -08:00
COPYING Provide missing COPYING file 2016-04-12 18:53:45 +00:00
EmailBlacklist.php Fix file permissions 2016-06-09 16:18:31 -07:00
extension.json Trigger Schema:ExternalLinksChange logging on page deletion 2016-09-29 14:14:01 +00:00
Gruntfile.js build: Configure banana-checker and jsonlint 2015-06-15 16:31:25 -07:00
package.json build: Updating development dependencies 2015-12-29 11:55:10 -08:00
README Merge "Log blacklist hits to Special:Log" 2013-09-08 00:58:41 +00:00
SpamBlacklist.php Add extensions.json, empty PHP entry point, remove i18n shim 2015-05-20 19:19:31 +01:00
SpamBlacklist_body.php Trigger Schema:ExternalLinksChange logging on page deletion 2016-09-29 14:14:01 +00:00
SpamBlacklistHooks.php Trigger Schema:ExternalLinksChange logging on page deletion 2016-09-29 14:14:01 +00:00
SpamBlacklistPreAuthenticationProvider.php Update for AuthManager 2016-05-11 22:32:49 +00:00
SpamRegexBatch.php Maintenance for SpamBlacklist extension. 2012-09-03 16:50:18 +02:00

MediaWiki extension: SpamBlacklist
----------------------------------

SpamBlacklist is a simple edit filter extension. When someone tries to save the
page, it checks the text against a potentially very large list of "bad"
hostnames. If there is a match, it displays an error message to the user and 
refuses to save the page.

To enable it, first download a copy of the SpamBlacklist directory and put it
into your extensions directory. Then put the following at the end of your 
LocalSettings.php:

require_once( "$IP/extensions/SpamBlacklist/SpamBlacklist.php" );

The list of bad URLs can be drawn from multiple sources. These sources are
configured with the $wgSpamBlacklistFiles global variable. This global variable
can be set in LocalSettings.php, AFTER including SpamBlacklist.php.

$wgSpamBlacklistFiles is an array, each value containing either a URL, a filename 
or a database location. Specifying a database location allows you to draw the
blacklist from a page on your wiki. The format of the database location
specifier is "DB: <db name> <title>".

Example:

require_once( "$IP/extensions/SpamBlacklist/SpamBlacklist.php" );
$wgSpamBlacklistFiles = array(
	"$IP/extensions/SpamBlacklist/wikimedia_blacklist", // Wikimedia's list

//          database    title
	"DB: wikidb My_spam_blacklist",
);

The local pages [[MediaWiki:Spam-blacklist]] and [[MediaWiki:Spam-whitelist]]
will always be used, whatever additional files are listed.

Compatibility
-----------

This extension is primarily maintained to run on the latest release version
of MediaWiki (1.22.x as of this writing) and development versions, however
the current version should work up to 1.21.

If you are using an older version of MediaWiki, you can checkout an
older release branch, for example MediaWiki 1.20 would use REL1_20.

For even older versions, you may be able to dig older versions out of the
Git repository which work, but if using Wikimedia's blacklist file
you will likely have problems with failure due to the large size of the
blacklist not being handled by old versions of the code.


File format
-----------

In simple terms:
   * Everything from a "#" character to the end of the line is a comment
   * Every non-blank line is a regex fragment which will only match inside URLs

Internally, a regex is formed which looks like this:

   !http://[a-z0-9\-.]*(line 1|line 2|line 3|....)!Si

A few notes about this format. It's not necessary to add www to the start of
hostnames, the regex is designed to match any subdomain. Don't add patterns
to your file which may run off the end of the URL, e.g. anything containing 
".*". Unlike in some similar systems, the line-end metacharacter "$" will not
assert the end of the hostname, it'll assert the end of the page.

Performance
-----------

This extension uses a small "loader" file, to avoid loading all the code on 
every page view. This means that page view performance will not be affected 
even if you are not running a PHP bytecode cache such as Turck MMCache. Note 
that a bytecode cache is strongly recommended for any MediaWiki installation.

The regex match itself generally adds an insignificant overhead to page saves,
on the order of 100ms in our experience. However loading the spam file from disk
or the database, and constructing the regex, may take a significant amount of
time depending on your hardware. If you find that enabling this extension slows
down saves excessively, try installing MemCached or another supported data
caching solution. The SpamBlacklist extension will cache the constructed regex 
if such a system is present.

Caching behavior
----------------

Blacklist files loaded from remote web sites are cached locally, in the cache
subsystem used for MediaWiki's localization. (This usually means the objectcache
table on a default install.)

By default, the list is cached for 15 minutes (if successfully fetched) or
10 minutes (if the network fetch failed), after which point it will be fetched
again when next requested. This should be a decent balance between avoiding
too-frequent fetches if your site is frequently used and staying up to date.

Fully-processed blacklist data may be cached in memcached or another shared
memory cache if it's been configured in MediaWiki.


Stability
---------

This extension has not been widely tested outside Wikimedia. Although it has
been in production on Wikimedia websites since December 2004, it should be 
considered experimental. Its design is simple, with little input validation, so
unexpected behavior due to incorrect regular expression input or non-standard
configuration is entirely possible.

Obtaining or making blacklists
------------------------------

The primary source for a MediaWiki-compatible blacklist file is the Wikimedia
spam blacklist on meta:

    http://meta.wikimedia.org/wiki/Spam_blacklist

In the default configuration, the extension loads this list from our site 
once every 10-15 minutes.

The Wikimedia spam blacklist can only be edited by trusted administrators. 
Wikimedia hosts large, diverse wikis with many thousands of external links, 
hence the Wikimedia blacklist is comparatively conservative in the links it 
blocks. You may want to add your own keyword blocks or even ccTLD blocks.
You may suggest modifications to the Wikimedia blacklist at:

    http://meta.wikimedia.org/wiki/Talk:Spam_blacklist

To make maintenance of local lists easier, you may wish to add a DB: source to
$wgSpamBlacklistFiles and hence create a blacklist on your wiki. If you do this,
it is strongly recommended that you protect the page from general editing.
Besides the obvious danger that someone may add a regex that matches everything,
please note that an attacker with the ability to input arbitrary regular
expressions may be able to generate segfaults in the PCRE library.

Whitelisting
------------

You may sometimes find that a site listed in a centrally-maintained blacklist
contains something you nonetheless want to link to.

A local whitelist can be maintained by creating a [[MediaWiki:Spam-whitelist]]
page and listing hostnames in it, using the same format as the blacklists.
URLs matching the whitelist will be ignored locally.

Logging
-------

To aid with tracking which domains are being spammed, this extension has
multiple logging features. By default, hits are included in the standard
debug log (controlled by $wgDebugLogFile). You can grep for 'SpamBlacklistHit',
which includes the IP of the user and the URL they tried to submit. This
file is only availible for people with server access and includes private info.

You can also enable logging to [[Special:Log]] by setting $wgLogSpamBlacklistHits to
true. This will include the account which tripped the blacklist, the page title the
edit was attempted on, and the specific URL. By default this log is only viewable
to wiki administrators, and you can grant other groups access by giving them the
"spamblacklistlog" permission.

Copyright
---------
This extension and this documentation was written by Tim Starling and is 
ambiguously licensed.