Jump to content

  •     

Photo

Getting Rid Of The Csfr Attack Crap


  • This topic is locked This topic is locked
5 replies to this topic

#1 Releasethe Krakken

Releasethe Krakken

    Advanced Member

  • Members
  • PipPipPip
  • 620 posts
  • LocationSouth of the clouds and north of the wind

Posted 14 December 2013 - 08:27 PM

It used to be that one would be thrown to a empty page or error page when your connection disconnected because you took too long to post an article or comment.

 

That was not as bad as one could hit the back button and find your article again.  Copy it and then paste it to your article.

 

Plato then fixed this and introduced a system were your drafts are supposedly saved.  However in many cases it aint and hitting the draft gets you a csfr attack screen or variable of that.. Hitting the back button dont help also.  I know your programmers do nothing but play haxball and troll in the off -topic forum but can you fix this please.

 

 


mh4l.png

 


#2 CheetahCurtis

CheetahCurtis

    Advanced Member

  • Members
  • PipPipPip
  • 281 posts

Posted 14 December 2013 - 08:33 PM

Do you know what a CSRF attack is?


AddJamaica_zpsb400a626.png

Add Caribbean Countries to eRepublik: http://tinyurl.com/kfrslg9

​I also eat babies and push elderly people off cliffs.


#3 Releasethe Krakken

Releasethe Krakken

    Advanced Member

  • Members
  • PipPipPip
  • 620 posts
  • LocationSouth of the clouds and north of the wind

Posted 14 December 2013 - 09:29 PM

yes its a post by an unauthorized user.  you login = authorized  user

 

you take too much time on a comment and your browser resets your connection to the site with no login details = unauthorized user

 

you post meaning Cross-site request forgery, also known as a one-click attack or session riding and abbreviated as CSRF (sometimes pronounced sea-surf[1]) or XSRF, is a type of malicious exploit of a website whereby unauthorized commands are transmitted from a user that the website trusts  the old page is up and transmits legit command but the site picks you up as logged out therefore its deemed a CSRF attack.


mh4l.png

 


#4 Releasethe Krakken

Releasethe Krakken

    Advanced Member

  • Members
  • PipPipPip
  • 620 posts
  • LocationSouth of the clouds and north of the wind

Posted 16 December 2013 - 12:00 AM

can a mod please respond to this?


mh4l.png

 


#5 Shiina Sayane

Shiina Sayane

    Advanced Member

  • Members
  • PipPipPip
  • 326 posts

Posted 16 December 2013 - 04:55 AM

no,its needed for security.


  • CheetahCurtis likes this

#6 elbandido

elbandido

    Advanced Member

  • Members
  • PipPipPip
  • 443 posts

Posted 16 December 2013 - 06:09 AM

It used to be that one would be thrown to a empty page or error page when your connection disconnected because you took too long to post an article or comment.

 

That was not as bad as one could hit the back button and find your article again.  Copy it and then paste it to your article.

 

Plato then fixed this and introduced a system were your drafts are supposedly saved.  However in many cases it aint and hitting the draft gets you a csfr attack screen or variable of that.. Hitting the back button dont help also.  I know your programmers do nothing but play haxball and troll in the off -topic forum but can you fix this please.

 

Hello, maybe THIS can help you, but I suggest you to make your article outside the game then publish it (notepad for example).

Regards.


...always watching...




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users