Jump to content

Security Alert: Possible Cross-Site Request Forgery (CSRF) or browser back button used.


sailing123

Recommended Posts

Sorry, me again ! I keep getting this message every so often:

"Security Alert: Possible Cross-Site Request Forgery (CSRF) or browser back button used."

Do I need to worry about this or am I doing something wrong here ? I am only amending text in site docs or products in the back end. I did not use any rbowser back button from what I can remember, just the save button.

Thanks

Link to comment
Share on other sites

This is a tough nut to crack. The most reasonable situation I have come across that throws this message is when the browser's "user-agent" string changes (or when the IP address, rarely, changes).

I am of the opinion that Chrome wants to update itself (complete with new version numbers) about 17 times a day.

I have also seen some weirdness where an admin will be using four or five completely different browsers (maybe just changing the u-a string to see what would happen) from the same IP address. Based on the evidence of the myriad of u-a strings, I initially thought that the admin was using a mobile device incorporated into their desktop, so as to share the same cookie. But I honestly don't know.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...