Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Keep getting "CSRF detected!"
#30
I have been experiencing CSRF for a few days recently. Some info on background situation:
  • I have several sites on GS 2.03 and 3.0, from which some share identical password and/or login
  • to one of them I have recently added:
Code:
ExpiresActive On
<FilesMatch "\.(ico|jpg|jpeg|png|gif|js|swf)$">
ExpiresDefault A2592000
</FilesMatch>
to .htaccess, which I rely on.

As impulse solutions I tried the following, from which some worked:
  • logged out, but afterwards admin/index.php redirected me automatically to admin/pages.php - in other words I couldn't log in properly until I deleted manually login cookie
  • turned off browser-cache (via WebDeveloper of Firefox) - worked once
  • logged in, saved a page, logged out - all with Google Chrome, which I have edited just this one site once - this worked and CSRF did not reappear in Firefox for a few days when I logged in, out and saved normally
  • logged in, saved a page, logged out - again with Google Chrome - this worked and CSRF did not reappear in Firefox for one login, some saves and a logout only - form next login CSRF was back.

I have purposefully pointed out this different scenarios and may be irrelevant info as can't see any consistency in browser behaviour - except for Chrome seems immune for CSRF in my case. I suspect it may be related to files handling by browser or server, but really have no idea. Hope someone sorts it out one day.

As a permament solution I launched into space line 36 of changedata.php and sleep sound.
Reply


Messages In This Thread
Keep getting "CSRF detected!" - by todoesverso - 2011-04-17, 01:25:12
Keep getting "CSRF detected!" - by Connie - 2011-04-17, 01:37:53
Keep getting "CSRF detected!" - by todoesverso - 2011-04-17, 01:49:19
Keep getting "CSRF detected!" - by mikeh - 2011-04-17, 04:54:47
Keep getting "CSRF detected!" - by todoesverso - 2011-04-17, 07:22:22
Keep getting "CSRF detected!" - by nitsuj - 2011-04-20, 05:26:56
Keep getting "CSRF detected!" - by snooze - 2011-04-20, 09:37:11
Keep getting "CSRF detected!" - by Connie - 2011-04-20, 14:53:06
Keep getting "CSRF detected!" - by nitsuj - 2011-04-20, 17:31:26
Keep getting "CSRF detected!" - by Connie - 2011-04-20, 18:56:24
Keep getting "CSRF detected!" - by nitsuj - 2011-04-20, 20:45:52
Keep getting "CSRF detected!" - by Connie - 2011-04-20, 21:16:44
Keep getting "CSRF detected!" - by snooze - 2011-04-27, 03:33:38
Keep getting "CSRF detected!" - by snooze - 2011-04-27, 03:42:28
Keep getting "CSRF detected!" - by Connie - 2011-04-27, 04:42:27
Keep getting "CSRF detected!" - by Aron - 2011-04-27, 07:59:16
Keep getting "CSRF detected!" - by ccagle8 - 2011-04-27, 10:54:10
Keep getting "CSRF detected!" - by snooze - 2011-04-28, 01:12:31
Keep getting "CSRF detected!" - by ccagle8 - 2011-04-28, 01:29:47
Keep getting "CSRF detected!" - by snooze - 2011-04-28, 04:58:16
Keep getting "CSRF detected!" - by Aron - 2011-04-29, 06:39:49
Keep getting "CSRF detected!" - by ccagle8 - 2011-04-29, 23:49:57
Keep getting "CSRF detected!" - by SamWM - 2011-05-06, 21:17:34
Keep getting "CSRF detected!" - by ccagle8 - 2011-05-06, 22:43:05
Keep getting "CSRF detected!" - by SamWM - 2011-05-28, 01:52:33
Keep getting "CSRF detected!" - by RobA - 2011-05-28, 02:43:19
Keep getting "CSRF detected!" - by SamWM - 2011-06-10, 19:06:16
Keep getting "CSRF detected!" - by yojoe - 2011-06-10, 23:41:44
Keep getting "CSRF detected!" - by SamWM - 2011-06-11, 02:42:26
Keep getting "CSRF detected!" - by Ampersand - 2012-02-03, 05:16:15
Keep getting "CSRF detected!" - by Connie - 2012-02-03, 16:27:35
Keep getting "CSRF detected!" - by Ampersand - 2012-02-10, 04:09:42
Keep getting "CSRF detected!" - by shawn_a - 2012-02-11, 04:47:00
Keep getting "CSRF detected!" - by bugmenot - 2012-04-03, 15:21:47
Keep getting "CSRF detected!" - by Connie - 2012-04-03, 16:33:41
Keep getting "CSRF detected!" - by rfuller - 2012-04-04, 03:00:46



Users browsing this thread: 5 Guest(s)