Last modified: 2012-12-13 11:45:14 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T44792, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 42792 - Wikidata blocks/blacklists certain IPs: "Your IP address is listed as an open proxy"
Wikidata blocks/blacklists certain IPs: "Your IP address is listed as an open...
Status: RESOLVED INVALID
Product: MediaWiki extensions
Classification: Unclassified
WikidataClient (Other open bugs)
master
All All
: Low trivial (vote)
: ---
Assigned To: Wikidata bugs
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2012-12-06 18:07 UTC by Alexandr Ignatiev
Modified: 2012-12-13 11:45 UTC (History)
8 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments
Screenshot (123.24 KB, image/jpeg)
2012-12-07 11:46 UTC, Alexandr Ignatiev
Details

Description Alexandr Ignatiev 2012-12-06 18:07:57 UTC
217.66.152.139 is dynamic IP by SPb MTS. I'm not an open proxy, I'm a mobile inet user, pls unblock me :*(
Comment 1 Platonides 2012-12-06 18:09:43 UTC
Where are you blocked, which error message do you get?
Comment 2 Alexandr Ignatiev 2012-12-06 20:41:19 UTC
It's on test-Wikidata client. I get error messages that my IP is open proxy while try to create account, feedback also doesn't work. I haven't find contacts of local admins, that's why I wrote here.
Comment 4 Platonides 2012-12-06 21:43:30 UTC
Alexandr, can you provide a screenshot of the error message you get?
Comment 5 Alexandr Ignatiev 2012-12-07 11:46:48 UTC
Created attachment 11480 [details]
Screenshot

The screenshot.
Comment 6 Platonides 2012-12-07 13:32:28 UTC
Seems that wikidata-test-client has $wgEnableDnsBlacklist = true;

I don't know which blacklist they are using. The obvious choice would be the SORBS http popen proxy list, but your ip doesn't seem to be listed there (139.152.66.217.http.dnsbl.sorbs.net returns No such name).

I have been asking for the name of the blacklist used.
Comment 7 Andre Klapper 2012-12-07 14:51:13 UTC
[[Extension:SpamBlacklist]] is used on wikidata.

I don't think we should manually change blocklists provided by 3rd parties.

Proposing to close this report as WONTFIX. You should contact SPb MTS to fix their open proxies, and you could ask the DNS blocklist operator to get the IP off the list.
But first I'd like to find out which DNS blocklist operator is used by Wikimedia.
Comment 8 Alexandr Ignatiev 2012-12-07 15:21:55 UTC
This DNS operator is used by not Wikimedia. In Wikipedia, I edit from this IP logged or unlogged without troubles.
Comment 9 Silke Meyer (WMDE) 2012-12-11 17:24:55 UTC
Hi, sorry for the late answer. I am using a DNS blacklist that is given as an example here: http://www.mediawiki.org/wiki/Manual:Combating_spam. I'll discuss the issue here in the team - we had a real spam problem earlier. Thanks for reporting - you are the first one to complain.
Comment 10 Platonides 2012-12-11 21:34:58 UTC
Short version: Alexandr, the cbl claims that you are infected with the festi spambot.


Long version:

The ip is listed in spamhaus:
139.152.66.217.xbl.spamhaus.org. 127.0.0.4 [this means it comes from CBL]

It can be consulted on http://www.spamhaus.org/query/bl?ip=217.66.152.139

It appears both in the pbl (for emails) and in the xbl (the one used by wikidata).

The entry in the xbl is there due to appearing in the cbl: http://cbl.abuseat.org/lookup.cgi?ip=217.66.152.139

«IP Address 217.66.152.139 is listed in the CBL. It appears to be infected with a spam sending trojan, proxy or some other form of botnet.

It was last detected at 2012-12-11 12:00 GMT (+/- 30 minutes), approximately 9 hours, 30 minutes ago.

This IP is infected (or NATting for a computer that is infected) with the festi spambot. In other words, it's participating in a botnet.

If you simply remove the listing without ensuring that the infection is removed (or the NAT secured), it will probably relist again.

This IP is infected (or NATting for a computer that is infected) with a spam-sending infection. In other words, it's participating in a botnet. If you simply remove the listing without ensuring that the infection is removed (or the NAT secured), it will probably relist again. »

It's interesting however that the CBL purpose is for email only «The CBL is intended to be used only on inbound email from the Internet.» (see the more lengthy explanation there)

Also see http://cbl.abuseat.org/tandc.html point 7

The faq for the XBL http://www.spamhaus.org/faq/section/Spamhaus%20XBL#155 seems less unhappy about it being used with non-email (although it is still recommending captchas, not blocks).

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links