<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Possible CSRF attack noted when asserting referer header in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/possible-csrf-attack-noted-when-asserting-referer-header/m-p/184208#M137338</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px; font-family: arial, helvetica, 'helvetica neue', verdana, sans-serif; color: #727174;"&gt;Hello everyone,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px; font-family: arial, helvetica, 'helvetica neue', verdana, sans-serif; color: #727174;"&gt;I have a problem after put my alfresco behind apache httpd:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ProxyPass&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /share&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://127.0.0.1:8081/share" rel="nofollow noopener noreferrer" target="_blank"&gt;http://127.0.0.1:8081/share&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ProxyPassReverse /share&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://127.0.0.1:8081/share" rel="nofollow noopener noreferrer" target="_blank"&gt;http://127.0.0.1:8081/share&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;Location “/share&amp;gt;&lt;/P&gt;&lt;P&gt;Order allow,deny&lt;/P&gt;&lt;P&gt;Allow from All&lt;/P&gt;&lt;P&gt;&amp;lt;/Location&amp;gt;&lt;/P&gt;&lt;P&gt;Getting error...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oct 19, 2016 12:35:42 PM org.apache.catalina.core.ApplicationContext log&lt;/P&gt;&lt;P&gt;INFO: No Spring WebApplicationInitializer types detected on classpath&lt;/P&gt;&lt;P&gt;Oct 19, 2016 12:36:41 PM org.apache.catalina.core.StandardWrapperValve invoke&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SEVERE: Servlet.service() for servlet [Spring Surf Dispatcher Servlet] in context with path [/share] threw exception [Possible CSRF attack noted when asserting referer header '&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://127.0.0.1/share/page" rel="nofollow noopener noreferrer" target="_blank"&gt;http://127.0.0.1/share/page&lt;/A&gt;&lt;SPAN&gt;'. Request: POST /share/page/dologin, FAILED TEST: Assert referer POST /share/page/dologin :: referer: '&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://127.0.0.1/share/page" rel="nofollow noopener noreferrer" target="_blank"&gt;http://127.0.0.1/share/page&lt;/A&gt;&lt;SPAN&gt;' vs server &amp;amp; context: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://127.0.0.1:8081/" rel="nofollow noopener noreferrer" target="_blank"&gt;http://127.0.0.1:8081/&lt;/A&gt;&lt;SPAN&gt; (string) or&amp;nbsp; (regexp)] with root cause&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;javax.servlet.ServletException: Possible CSRF attack noted when asserting referer header '&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://127.0.0.1/share/page" rel="nofollow noopener noreferrer" target="_blank"&gt;http://127.0.0.1/share/page&lt;/A&gt;&lt;SPAN&gt;'. Request: POST /share/page/dologin, FAILED TEST: Assert referer POST /share/page/dologin :: referer: '&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://127.0.0.1/share/page" rel="nofollow noopener noreferrer" target="_blank"&gt;http://127.0.0.1/share/page&lt;/A&gt;&lt;SPAN&gt;' vs server &amp;amp; context: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://127.0.0.1:8081/" rel="nofollow noopener noreferrer" target="_blank"&gt;http://127.0.0.1:8081/&lt;/A&gt;&lt;SPAN&gt; (string) or&amp;nbsp; (regexp)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.alfresco.web.site.servlet.CSRFFilter$AssertRefererAction.run(CSRFFilter.java:1017)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.alfresco.web.site.servlet.CSRFFilter.doFilter(CSRFFilter.java:312)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:241)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:208)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.alfresco.web.site.servlet.SSOAuthenticationFilter.doFilter(SSOAuthenticationFilter.java:450)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:241)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:208)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.alfresco.web.site.servlet.MTAuthenticationFilter.doFilter(MTAuthenticationFilter.java:74)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:241)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:208)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:220)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:122)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:504)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:170)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:103)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.catalina.valves.AccessLogValve.invoke(AccessLogValve.java:950)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:116)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:421)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.coyote.http11.AbstractHttp11Processor.process(AbstractHttp11Processor.java:1074)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.coyote.AbstractProtocol$AbstractConnectionHandler.process(AbstractProtocol.java:611)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.tomcat.util.net.AprEndpoint$SocketProcessor.doRun(AprEndpoint.java:2466)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.tomcat.util.net.AprEndpoint$SocketProcessor.run(AprEndpoint.java:2455)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)&lt;/P&gt;&lt;P&gt;&amp;nbsp; at java.lang.Thread.run(Unknown Source)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Oct 2016 07:25:46 GMT</pubDate>
    <dc:creator>ppg</dc:creator>
    <dc:date>2016-10-19T07:25:46Z</dc:date>
    <item>
      <title>Possible CSRF attack noted when asserting referer header</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/possible-csrf-attack-noted-when-asserting-referer-header/m-p/184208#M137338</link>
      <description>Hello everyone,I have a problem after put my alfresco behind apache httpd&lt;IMG id="smileytongue" class="emoticon emoticon-smileytongue" src="https://migration33.stage.lithium.com/i/smilies/16x16_smiley-tongue.png" alt="Smiley Tongue" title="Smiley Tongue" /&gt;roxyPass&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /share&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; http://127.0.0.1:8081/shareProxyPassReverse /share&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; http://127.0.0.1:8081/share&amp;lt;Location “/share&amp;gt;Order allow,denyAllow from All&amp;lt;/Location&amp;gt;Getting error...Oct 19, 2016 12:35:42 PM org.apa</description>
      <pubDate>Wed, 19 Oct 2016 07:25:46 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/possible-csrf-attack-noted-when-asserting-referer-header/m-p/184208#M137338</guid>
      <dc:creator>ppg</dc:creator>
      <dc:date>2016-10-19T07:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: Possible CSRF attack noted when asserting referer header</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/possible-csrf-attack-noted-when-asserting-referer-header/m-p/184209#M137339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Buenas:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Simplemente esta cantando una policy de seguridad que tiene Alfresco Share (CSRF - &lt;SPAN style="color: #222222; font-family: arial, sans-serif; font-size: 16px;"&gt;Cross-site request forgery&lt;/SPAN&gt;).&lt;/P&gt;&lt;P&gt;Estas policies se configuran en el archivo $ALF_HOME/tomcat/shared/classes/alfresco/web-extension/share-config-custom.xml&amp;nbsp; &lt;/P&gt;&lt;P&gt;Si quieres deshabilitar las policies de CSRF puedes hacerlo descomentando esta sección en el archivo: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; &amp;lt;!-- Disable the CSRF Token Filter --&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; &amp;lt;!--&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; &amp;lt;config evaluator="string-compare" condition="CSRFPolicy" replace="true"&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;filter/&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; &amp;lt;/config&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; --&amp;gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Aunque lo más adecuado es decirle a Alfresco qué hosts pueden hacerle peticiones de proxy.&lt;/P&gt;&lt;P&gt;Puedes leer más sobre CSRF en el whitepaper de &lt;B&gt;toni.delafuente _&lt;/B&gt;​&amp;nbsp; "Alfresco Security White Paper":&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://blyx.com/2014/10/08/my-talk-about-alfresco-security-best-practices-at-the-alfresco-summit-2014/" title="http://blyx.com/2014/10/08/my-talk-about-alfresco-security-best-practices-at-the-alfresco-summit-2014/" rel="nofollow noopener noreferrer"&gt;My talk about “Alfresco Security Best Practices” at the Alfresco Summit 2014 – : : blyx.com : : Blog : : Toni de la Fuen…&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Saludos.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--C.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Oct 2016 09:08:39 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/possible-csrf-attack-noted-when-asserting-referer-header/m-p/184209#M137339</guid>
      <dc:creator>cesarista</dc:creator>
      <dc:date>2016-10-19T09:08:39Z</dc:date>
    </item>
  </channel>
</rss>

