RECESSIM:Handling vandalism

This page is for administrators (sysops). It explains how to spot, undo and prevent vandalism on RECESSIM. Almost everything on a wiki is reversible: every edit is kept in page history, and deleted pages can be restored.

1. Spotting problems

  • Special:RecentChanges: every edit. Edits that nobody has reviewed yet show a red ! ("unpatrolled"). Click diff, then Mark as patrolled once you're happy with an edit.
  • Tags: five automatic filters tag suspicious edits in Recent Changes. They never block anyone.
    • av-blanking: a page was emptied (over 500 bytes down to under 50).
    • av-large-removal: more than 5 KB removed in one edit.
    • av-link-dump: more than 10 external links added in one edit.
    • av-repeated-chars: keyboard mashing (one letter g–z repeated 30+ times; hex dumps are ignored).
    • av-page-move: any page move (moves are rare here).
  • Special:AbuseLog: the full list of filter hits, with the exact edit details. Manage the filters at Special:AbuseFilter.
  • Keep an eye on changes: watch important pages (star icon), or subscribe to the Recent Changes feed (Atom link in the sidebar of Special:RecentChanges).

2. Undoing damage

  • One bad edit: open the page's History and click undo on that edit.
  • Several bad edits in a row by one user: click rollback in the history or on Recent Changes. It reverts all of that user's consecutive latest edits in one click. Sysops and members of the trusted group have rollback.
  • Restore an older good version: in History, open the good revision, click Edit, and save it with a summary such as "Restore version of <date>".
  • A moved page: move it back (the Move tab), and delete the leftover redirect if needed.
  • Lots of junk pages from one account: Special:Nuke lists every page that account created, so you can mass-delete them.
  • Deleted by mistake: Special:Undelete.

3. Stopping it

  • Block the account: Special:Block. Use a short block for a first offence and indefinite for obvious vandal-only accounts. Leave "Autoblock" ticked so the IP address is blocked too.
  • Remove editing rights: Special:UserRights. Take the account out of writer; sysops can add or remove writer and trusted.
  • Ban evasion or sockpuppets: Special:CheckUser shows which accounts share IP addresses (CheckUser right only).
  • Protect a page under attack: the Protect tab (admins only, set an expiry). High-use templates are already permanently protected.

4. Giving people the right level of access

  • writer: can edit and create pages. Granted after someone introduces themselves on Discord.
  • trusted: writer plus rollback, and their own edits are marked as reviewed automatically. Give this to reliable regular editors.
  • sysop: everything above plus delete, block, protect and filters. Keep this group small.
  • Writer rights are removed from accounts that have been inactive for over 12 months. Anyone can ask on Discord to have them restored.

5. Worst case: restoring from backup

If the wiki is badly damaged (for example a compromised admin account, mass deletion, or database problems), the server makes a full backup every Sunday (database, uploaded files, settings). A copy is pulled to off-site storage.

  • On the server, backups are in /var/backups/wiki/ (the newest two, with latest pointing at the most recent). Each one contains a README.txt with step-by-step restore instructions.
  • A restore is a server-level job: contact Hash. Undoing edits through History (above) is almost always the better option.