minibb®
Fight the automated spam - protect your miniBB-forums,
getting the Captcha addon! Click here to read more.
Captcha Addon for miniBB
Community Forum
 | Forums | File Bank | Sign Up | Search | Statistics | Manual |
Specific miniBB Community Forum / Specific /

Can not proceed: possible CSRF/XSRF attack!

 
Buzz
Forums Member
#1 | Posted: 20 Aug 2008 14:21
After upgrading, when I as Admin try to delete a post, I get this message:
Can not proceed: possible CSRF/XSRF attack!

What does that mean?
Paul
CEO
#2 | Posted: 21 Aug 2008 02:51 | Edited by: Paul
It could mean that for some reason the CSRF-checking cookie was not set upon your login. Try to log-out and log-in again.

Without deep investigation I can't say precisely what the problem could be.

If you can't repeat the same on our test forums, it could mean the error is somewhere on your side.
Buzz
Forums Member
#3 | Posted: 21 Aug 2008 04:36
I have tried to log out en logged in again, but the error remains. today I checked it on another computer and that is the same.

How can I reset the CRF cookie, or disable it?
Paul
CEO
#4 | Posted: 21 Aug 2008 04:49
You can't disable CSRF cookie because it's a part of the security mechanism.

Are you sure you just installed the default version of the board? None of custom modifications are made? What kind of browser are you using?

If you log-in on our site it only proves everything works correctly.

You may try to completely clear all cookies from your domain as well before log-in.
Buzz
Forums Member
#5 | Posted: 21 Aug 2008 04:57
thank you for your quick response.

It is the latest version, I have updated from 2.03.
You can see the board here: http://www.hondacx500.nl/ (click on Prikbord, it opens in a frame)

I use these plugins:
1. Avatars
2. Signature
3 Captcha
4. 1st news hack

If you wish, I can give you the admin login codes.
Buzz
Forums Member
#6 | Posted: 21 Aug 2008 12:12
I hope that you can help me, as an Admin now is it impossible to delete messages. The strange thing is that I can edit.
tom322
Forums Member
#7 | Posted: 21 Aug 2008 12:45
I think it's a custom problem so you'd have to pay for the time to resolve it...
Paul
CEO
#8 | Posted: 21 Aug 2008 16:39 | Edited by: Paul
Buzz: please drop me an email on ghappa [at] gmail dot com and provide me at least your admin login details so I can check what's going on. If it will be your custom trouble, you will need to pay out our service, but I hope it all won't exceed $10. If it will be our problem, no charge. Thanks.

P.S. Yes, CSRF works for deleting topic/messages and other stuff in the current version. So as soon the CSRF cookie is not set, it won't allow to delete anything. The problem also could be that your forums is called from a frame.
Buzz
Forums Member
#9 | Posted: 26 Aug 2008 04:12
Paul,

I think it is solved: I have installed a complete new version instead of upgrading the existing one.
Anyway, thanks for your last reply and help Paul.
 
This topic is closed. You can't post a reply.
 
Online now: Guests - 31
Members - 0
Most users ever online: 191 [24 Dec 2007 14:33]
Guests - 191 / Members - 0

Forums are powered by miniBB®