Jump to content

Help:CheckUser/id: Difference between revisions

From Meta, a Wikimedia project coordination wiki
Content deleted Content added
Created page with "Pemeriksa Wikimedia memiliki akses ke milis pribadi $listName. Mereka mungkin menggunakan milis ini untuk berdiskusi atau mendapatkan bantuan, ide, dan opini kedua."
No edit summary
Line 28: Line 28:
=== Milis ===
=== Milis ===


Pemeriksa Wikimedia memiliki akses ke milis pribadi ''[[mail:checkuser-l|checkuser-l]]''. Mereka mungkin menggunakan milis ini untuk berdiskusi atau mendapatkan bantuan, ide, dan opini kedua.
Pemeriksa Wikimedia memiliki akses ke milis pribadi ''[[mail:checkuser-l|checkuser-l]]''. Mereka mungkin menggunakan milis ini untuk berdiskusi atau mendapatkan bantuan, ide, dan meminta opini kedua.


=== Notes ===
=== Notes ===

Revision as of 02:21, 14 September 2021

Halaman ini adalah manual teknis untuk halaman khusus CheckUser dengan pertimbangan khusus Wikimedia. Untuk ekstensi CheckUser sendiri, lihat halaman ekstensi CheckUser di situs web www.mediawiki.org.

Special:CheckUser memungkinkan pengguna dengan hak checkuser untuk mengakses data rahasia yang disimpan tentang pengguna, alamat IP, atau rentang CIDR. Data ini mencakup alamat IP yang digunakan oleh pengguna, semua pengguna yang menyunting dari alamat atau rentang IP, semua suntingan dari alamat atau rentang IP, string User agent, dan header X-Forwarded-For.

Alat ini biasanya digunakan untuk mengatasi akun boneka/akun siluman yang memiliki niat buruk. (Catatan: checkuser atau pemeriksa dapat merujuk pada akses ke informasi rahasia, pengguna yang memiliki izin untuk melakukannya, atau sebagai penanda teknis.)

Pertimbangan

Kebijakan Privasi dan Kerahasiaan Wikimedia

Pemeriksa di bawah Yayasan Wikimedia tunduk pada ketentuan penggunaan, kebijakan privasi, akses ke kebijakan informasi nonpublik, kebijakan CheckUser dan perjanjian kerahasiaan untuk informasi nonpublik. Mengungkapkan data rahasia yang tersimpan tentang pengguna dilarang kecuali pada serangkaian kasus terbatas yang dirinci dalam kebijakan yang disebutkan di atas.

Jika memungkinkan, pemeriksa harus berusaha menyelesaikan situasi tanpa mengungkap informasi apa pun, atau dengan mengungkap informasi seminimal mungkin. Informasi berikut biasanya diperbolehkan. Daftar ini tidak komprehensif, dan tidak dapat menggantikan penilaian pemeriksa. Jika pemeriksa sama sekali ragu, mereka tidak boleh memberikan detail dan sebaiknya beri jawaban seperti Magic 8-Ball:

  • konfirmasi bahwa seorang pengguna adalah akun boneka tanpa mengindikasikan informasi pribadi;
  • informasi yang dirilis oleh pengguna;
  • ISP yang digunakan untuk menyunting, jika cukup besar sehingga informasinya tidak dapat diidentifikasi secara pribadi;
  • negara, yang umumnya tidak dapat diidentifikasi secara pribadi.

Milis

Pemeriksa Wikimedia memiliki akses ke milis pribadi checkuser-l. Mereka mungkin menggunakan milis ini untuk berdiskusi atau mendapatkan bantuan, ide, dan meminta opini kedua.

Notes

  • CheckUser is not magic wiki pixie dust. Almost all queries about IPs will be because two editors were behaving the same way. An editing pattern match is the important thing; the IP match is really just extra evidence (or not).
  • Most dialup and a lot of DSL and cable IPs are dynamic. They might change every session, every day, every week, every few months or hardly ever. Unless the access times are right next to each other, be cautious in declaring a match. After a while, you get to know which ISPs change quickly or slowly.
  • If it's a proxy, it might not be a match, depending on the size of the organisation running the proxy (per whois output). If it's an ISP proxy, it is not so likely to be a match.
  • If it's an AOL address, you're out of luck — AOL sends each page request through a different proxy.
  • If a username is using lots of different IPs in various countries, the IPs may well be open proxies. Check with an open proxy checker.
  • Edits from addresses allocated to hosting facilities almost always indicates the use of compromised hosting servers to nefarious ends. Note, however, that the user may have a legitimate shell account on the machine.
  • For IPv6 addresses, you may wish to check the user's entire /64 subnet, because it is possible that the user may be using more than one address out of their range.

Useful tools

"Unix" here includes Unix-like, Linux and Mac OS X computers.

  • whois: On Unix, start a terminal and type whois [IP address] at the command line. This should tell you who owns the IP, what the range is and may also note what they use it for. On Windows, All Net Tools has a pretty good web-based whois (which does an nslookup as well).
  • nslookup: On Unix or Windows, nslookup [IP address] at the command line will give you the fully qualified domain name associated with the IP. Note that not all IPs have a domain name, so don't worry if nothing comes back. If you're on Windows, the All Net Tools whois also gives you the FQDN.
  • traceroute: With IPs from some Internet Service Providers it may be useful to use the traceroute command and compare the results between two or more IPs. The site All Net Tools also gives you traceroute function if you don't have it as a command line.
    • tcptraceroute: A version of traceroute that uses TCP packets, which get through some firewalls and packet filters that stop ICMP packets. You can get source code for Unix-like systems; else, most Linux distributions have a package available with it.
  • Open proxy checking: David has yet to find a good tool for this. (proxycheck doesn't do what I want.) There are a number of online proxy checkers: [1], Nmap. (I have not tried them.) Help needed. I usually work on a combination of online proxy list checking and educated guesswork ;-) w:en:User:Tawker runs a web-based proxy checker. To request access to it, contact him on his talk page.
  • Checks for other abuse of an IP: rbls.org gives the status of any IP address on a number of Realtime Blackhole Lists. Note that some RBL blocks should be expected, e.g. many block home dynamic IPs for SMTP, but that's not a problem for a wiki. If a user only uses open proxies or addresses marked as sources of abuse, your suspicions may be raised.
  • Related anon contributions: rangecontribs tool gives anon edits from a given subnet (dead link).

Usage

Basic interface

  1. Go to Special:CheckUser (make sure you are on a wiki where you have access).
  2. In the user field, type in the username (without the 'user:' prefix), IP address, or CIDR range.
    • IP: any IPv4 (most common) or IPv6 address.
    • CIDR: you can check a range of IP addresses by appending the CIDR prefix (up to /16 for IPv4 (65,536 addresses) or /48 (1,208,925,819,614,629,174,706,176 addresses) for IPv6). For notation, see Range blocks.
    • XFF: you can check a client IP address provided by X-Forwarded-For headers by appending /xff (for example, 127.0.0.1/xff).
  3. Select the information you want to retrieve.
    • Get IPs: returns IP addresses used by a registered user.
    • Get edits from IP: returns all edits made by a user (registered or anonymous) from an IP address or range.
    • Get users: returns user accounts that have edited from an IP or range.
  4. In the reason field, type in the reason you are accessing the confidential data. Try to succinctly summarise the situation (for example, "cross-wiki spam"); this will be logged. This may be needed by the Ombudsman Commission.

Information returned

A typical entry in the checkuser results for a user summary ("get users") is as follows:

  • Example (Talk | contribs) (20:11, 21 Agustus 2026 -- 20:12, 21 Agustus 2026) [5]
    1. 127.0.0.37 XFF: 127.0.0.1, 127.0.0.5
    2. Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.11) Gecko/20070312 Firefox/1.5.0.11

This is formatted to fit a lot of information into a format that can very easily be listed and skimmed, but is difficult to read unless you know what the information provided is. The information is laid out as follows:

  • username (user links) (time period when they edited from the given IP or range) [number of edits from the IP or range]
    1. IP address edited from XFF: XFF information provided (can be spoofed)

Each IP/XFF combination used to edit is listed, in order of use.

The last ten user agents (browser, operating system, system language, and versions) for each user for edits made in the IP or range are listed afterwards.

XFF Format

XFF (X-Forwarded-For) headers indicate the series of IP addresses used from the user's computer (first) to the server hosting MediaWiki (last).

In this example:

aaa.aaa.aaa.aaa XFF: 10.4.46.42, 127.0.0.1, aaa.aaa.aaa.aaa, 208.80.152.46

  • the first two addresses (10.4.46.42, 127.0.0.1) are private to the originating network and can't be reached directly from the public Internet,
  • the third address (aaa.aaa.aaa.aaa) is the "public face" of the editor, usually a broadband or dialup ISP, a company gateway, (but possibly an anonymizer or a malware-compromised server),
  • the last address (208.80.152.46) is one of the Wikimedia squids (sq36.wikimedia.org).
Help contents
Meta · Wikinews · Wikipedia · Wikiquote · Wiktionary · Commons: · Wikidata · MediaWiki · Wikibooks · Wikisource · MediaWiki: Manual · Google
Versions of this help page (for other languages see further)
What links here on Meta or from Meta · Wikipedia · MediaWiki
Reading
Go · Search · Namespace · Page naming · Section · Backlinks · Redirect · Category · Image page · Special pages · Printing
Tracking changes
Recent changes (enhanced) | Related changes · Watching pages · Diff · Page history · Edit summary · User contributions · Minor edit · Patrolled edit
Logging in and preferences
Logging in · Preferences
Editing
Starting a new page · Advanced editing · Editing FAQ · Export · Import · Shortcuts · Edit conflict · Page size
Referencing
Links · URL ·  · Footnotes
Style and formatting
Wikitext examples · CSS · Reference card · HTML in wikitext · Formula · Lists · Table · Sorting · Colors · Images and file uploads
Fixing mistakes
Show preview · Reverting edits
Advanced functioning
Expansion · Template · Advanced templates · Parser function · Magic words · System message · Substitution · Arrays · Expr parser function syntax · Transclusion
Others
Special characters · Renaming (moving) a page · Preparing a page for translation · Talk pages · Signatures · Sandbox · Legal issues for editors