[GH-ISSUE #1038] Limit wiki edit permissions #649

Closed
opened 2026-03-01 14:45:17 +03:00 by kerem · 2 comments
Owner

Originally created by @antiops on GitHub (Oct 20, 2022).
Original GitHub issue: https://github.com/ArchiveBox/ArchiveBox/issues/1038

Noticed some sus links in the wiki while going through the history, an IP logger and some zip files that probably got removed by GitHub. I reverted the edits that I found to whatever they used to be, they only started to pop up a couple months ago on those 2 pages.

Restricting editing to collaborators should probably be enabled so the pages cant be edited/created/deleted by anyone.

1
2
3

Originally created by @antiops on GitHub (Oct 20, 2022). Original GitHub issue: https://github.com/ArchiveBox/ArchiveBox/issues/1038 Noticed some sus links in the wiki while going through the history, an IP logger and some zip files that probably got removed by GitHub. I reverted the edits that I found to whatever they used to be, they only started to pop up a couple months ago on those 2 pages. Restricting editing to collaborators should probably be enabled so the pages cant be edited/created/deleted by anyone. ![1](https://user-images.githubusercontent.com/22041463/196993530-cc760542-55d8-45fa-95db-d5595b8137d3.png) ![2](https://user-images.githubusercontent.com/22041463/196993520-196ddfd5-a98b-405c-becf-855ae44dc31d.png) ![3](https://user-images.githubusercontent.com/22041463/196993533-2103abff-85f1-4746-87ed-d3551e0efb4b.png)
kerem 2026-03-01 14:45:17 +03:00
Author
Owner

@pirate commented on GitHub (Oct 27, 2022):

Thank you so much for alerting me of this! I just changed the edit permissions.

Sad to see they were being abuse for malware links, it makes sense but didn't think to check for this myself.

I'd like to send you a $50 bounty for discovering this. Whats your preferred method? I can send with Venmo/Zelle/ETH/BTC/XMR/USDC

<!-- gh-comment-id:1293525105 --> @pirate commented on GitHub (Oct 27, 2022): Thank you so much for alerting me of this! I just changed the edit permissions. Sad to see they were being abuse for malware links, it makes sense but didn't think to check for this myself. I'd like to send you a $50 bounty for discovering this. Whats your preferred method? I can send with Venmo/Zelle/ETH/BTC/XMR/USDC
Author
Owner

@antiops commented on GitHub (Oct 31, 2022):

I'd love it if you could donate it to Archive.org, it'd be put to much better use than in my pocket :bowtie:

<!-- gh-comment-id:1296526672 --> @antiops commented on GitHub (Oct 31, 2022): I'd love it if you could donate it to Archive.org, it'd be put to much better use than in my pocket :bowtie:
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/ArchiveBox#649
No description provided.