Wikipedia:Requests for checkuser/Case/Cplot

''The following discussion is preserved as an archive of a Request for checkuser. Please do not modify it .''

Cplot 8



 * Code Letter: F

Used to harass user here Reference to espionage, MONGO and Morton_devonshire smells like Cplot. --Tbeatty 04:59, 15 March 2007 (UTC)
 * Merged from Requests for checkuser/Case/Guerillamarketing. – Luna Santin  (talk) 05:04, 15 March 2007 (UTC)

Cplot has made no recent edits. The Uninvited Co., Inc. 21:26, 21 March 2007 (UTC)

Cplot 7


This is a crosspost from Special:Log/block; they were ✅ by Mackensen - see block logs. Daniel.Bryant [ T · C ] 03:24, 4 January 2007 (UTC)

Cplot 6.0

 * , based on this.
 * Code letter: A, C, F
 * , based on this.
 * Code letter: A, C, F
 * , based on this.
 * Code letter: A, C, F
 * , based on this.
 * Code letter: A, C, F
 * , based on this.
 * Code letter: A, C, F
 * , based on this.
 * Code letter: A, C, F
 * , based on this.
 * Code letter: A, C, F
 * , based on this.
 * Code letter: A, C, F
 * , based on this.
 * Code letter: A, C, F
 * , based on this.
 * Code letter: A, C, F
 * , based on this.
 * Code letter: A, C, F
 * , based on this.
 * Code letter: A, C, F
 * , based on this.
 * Code letter: A, C, F
 * , based on this.
 * Code letter: A, C, F
 * , based on this.
 * Code letter: A, C, F
 * , based on this.
 * Code letter: A, C, F
 * Code letter: A, C, F

Latest dump from Suspected sock puppets/Cplot. These puppets have appeared since the last checkuser run on the 28th of December or haven't been checkusered yet to the best of my knowledge. MER-C 09:45, 2 January 2007 (UTC)

✅ all except the last one (Purgeusdhs). Also confirm anything from the last twenty minutes or so in my block log. A number of these I already checked and blocked over the last few weeks. Mackensen (talk) 03:15, 3 January 2007 (UTC)
 * for documentation's sake, here is the list of usernames blocked by Mackensen per above:-
 * The IP's used are not listed. Daniel.Bryant [ T · C ] 03:24, 3 January 2007 (UTC)
 * The IP's used are not listed. Daniel.Bryant [ T · C ] 03:24, 3 January 2007 (UTC)
 * The IP's used are not listed. Daniel.Bryant [ T · C ] 03:24, 3 January 2007 (UTC)
 * The IP's used are not listed. Daniel.Bryant [ T · C ] 03:24, 3 January 2007 (UTC)
 * The IP's used are not listed. Daniel.Bryant [ T · C ] 03:24, 3 January 2007 (UTC)
 * The IP's used are not listed. Daniel.Bryant [ T · C ] 03:24, 3 January 2007 (UTC)

Cplot
He's baaaaaaack (or did he never really leave?).—Ryūlóng ( 竜龍 ) 08:52, 23 December 2006 (UTC) This is not an IP check. Please put it on the request page for Cplot, and relist it in pending cases. Essjay  ( Talk )  05:42, 24 December 2006 (UTC)
 * These are all ✅ also. They were all part of the latest attack, the accounts other admins blocked before me, which I think I stopped with a timely range block when it was happening. Dmcdevit·t 07:45, December 24, 2006
 * moved per Essjay, and archived immediately because there is no point on relisting it on the main RFCU page. Daniel.Bryant [ T · C ] 11:15, 24 December 2006 (UTC)

Cplot 4



 * Code letter: ACF
 * Code letter: ACF
 * Code letter: ACF
 * Code letter: ACF
 * Code letter: ACF

The deleted edits at these sockpuppets' talk pages give them away. I hope they didn't slip through the cracks. MER-C 09:02, 16 December 2006 (UTC)

Added, declining this request while impersonating Essjay and this. MER-C 09:29, 16 December 2006 (UTC)

✅. Essjay   ( Talk )  23:38, 16 December 2006 (UTC)

Cplot 3rd Request





 * Code letter: ACF

User:SavoirFaireIsEverywhere was created on December 2nd, and made their first edit to their own user page. This matches a pattern seen with other Cplot socks. The user also made an edit on Talk:Helmut Jahn about something relating to Chicago where Cplot apparently is from. Then, on December 8th, the user came on the September 11, 2001 attacks, with an edit summary "see length ongoing discussion on talk page and throughout Wikipedia administrative pages" and made some more edits that are characteristic of Cplot socks. (e.g.   )  I'm fairly sure this is another Cplot sock, but since I'm involved with those pages, I would like to be more sure of it before doing a block (or better yet, someone uninvolved do the block). --Aude (talk) 16:22, 13 December 2006 (UTC)


 * Added another cplot sock per notice by Mackensen on ANI. Syrthiss 18:31, 14 December 2006 (UTC)
 * And another. Gonna be a busy day. Tony Fox (arf!) 18:56, 14 December 2006 (UTC)

✅. Also: I've changed some of Mackensen's previous anon-only IP blocks to full blocks, since he's been registering accounts on other IPs and using them on blocked ones. Dmcdevit·t 22:36, 14 December 2006 (UTC)


 * Thank you. --Aude (talk) 22:43, 14 December 2006 (UTC)

Cplot 2nd Request



 * Code letter: ACF
 * Code letter: ACF
 * Code letter: ACF
 * Code letter: ACF

Also these (from the Cplot sockpuppet case):
 * - Obvious sockpuppet from contribs and language
 * - Same massive copy/paste post as previous socks
 * - Another copy/paste
 * - Found from a copy/paste signature
 * - Found from looking at frequently posted pages
 * - Found from looking at frequently posted pages
 * - Found from looking at frequently posted pages
 * - In the new user log
 * - Done after range blocks of 68.30.x.x and 70.8.x.x
 * - Copy/paste "clowns" diatribe
 * - more "clowns" crap
 * - From deleted page Clowns
 * - clowns and conspiracy theories
 * - Attack only activity related to Cplot issues
 * more of the same
 * - From deleted page Clowns
 * - clowns and conspiracy theories
 * - Attack only activity related to Cplot issues
 * more of the same

See Tbeatty 03:25, 7 December 2006 (UTC)

We need an IP range to block. --Tbeatty 00:27, 7 December 2006 (UTC)

See WP:ANI. ClownsAreCowards is a new account created after the range blocks. User might be on another Sprint PCS or other ISP range now? Feel free to e-mail me, if this needs to be discussed privately. --Aude (talk) 22:28, 4 December 2006 (UTC)

. I'm working on it. Please stand by. Mackensen (talk) 00:32, 8 December 2006 (UTC)


 * Take your time. The block on those two IP ranges seems to help (another 24+ hours for it), though not 100%.  There may be some other ranges we are missing, that need to be blocked if the problem persists.  Range blocks are regrettable, but needed if the ISP doesn't work with us.  Given Essjay's previous reply, I don't think there are many other users on those ranges. Any advice on all this would most appreciated.  Thank you for assisting. --Aude (talk) 00:42, 8 December 2006 (UTC)

Without going into all the gory details (and my, are they gory), this fellow has availed himself of over a half-dozen different ISPs within the greater Chicago area, so actually nailing him will prove complicated. I concur in the range-blocks of 68.30.0.0/16 and 70.8.0.0/16; if these have lapsed they need to be re-imposed immediately. In addition, I have pinpointed a couple Illinois Comcast addresses which I'll be hitting with lengthy disruption blocks. There are a couple other public IPs that would cause too much collateral damage. Mackensen (talk) 00:55, 8 December 2006 (UTC)


 * These probably include Illinois Century Networks and the Comcast IP listed on Suspected sock puppets/Cplot. Cplot seemed to come out in force last night when the range blocks lapsed.  Whatever you judge best to do is fine with me.  Thank you for working on this.  Most appreciated. --Aude (talk) 01:10, 8 December 2006 (UTC)

Cplot

 * 
 * -
 * others from same ISP
 * -
 * others from same ISP
 * -
 * others from same ISP
 * -
 * others from same ISP
 * others from same ISP
 * others from same ISP
 * others from same ISP
 * others from same ISP
 * others from same ISP
 * others from same ISP


 * Code letter: CF

User:Cplot has been indefinitely blocked for trolling, personal attacks, incivility, and disruption on articles relating to the September 11, 2001 attacks. See WP:ANI for details. These IPs listed have been editing various policy and project pages, such as the Help Desk and Village pump (news), and Village_pump_%28miscellaneous%29 and targeting user talk pages. 

The IPs come from Sprint PCS. I think perhaps the user has sprint wireless broadband, where the IP changes each time one logs on the Internet. It only takes a minute to log off and on again, so the user can repeatedly do that and evade blocks. As a result, Talk:September 11, 2001 attacks has been semi-protected.

See also: Suspected_sock_puppets

While blocking may not be the answer, I'd like this pursued further, such as on WP:ABUSE, if this is Cplot evading his/her indef block. --Aude (talk) 01:52, 1 December 2006 (UTC)

I have blocked a few:

But, the user comes back after a couple minutes with a new IP. --Aude (talk) 02:16, 1 December 2006 (UTC)

Cplot is definately in the 68.30 /16, there is no sign of him in 70.8.0.0/16. User:HowAboutThisNameThen, who was blocked yesterday, is also in that /16. The good news is, there isn't much of anyone else in the /16's, so if they are creating problems, an anon-only block of either or both (keep it short) would be fine. Essjay  ( Talk )  09:30, 2 December 2006 (UTC)
 * Thank you.--MONGO 09:35, 2 December 2006 (UTC)

''The above discussion is preserved as an archive of the Request for checkuser. Please do not modify it. Subsequent requests related to this user should be made above, in a new section.''