<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 4.2.f  Possible CSRF attack noted when asserting referer header in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/4-2-f-possible-csrf-attack-noted-when-asserting-referer-header/m-p/305640#M258770</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello everyone,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have a problem after put my alfresco behind apache httpd:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;VirtualHost *:80&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProxyPass /share &lt;/SPAN&gt;&lt;A href="http://127.0.0.1:8181/share" rel="nofollow noopener noreferrer"&gt;http://127.0.0.1:8181/share&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProxyPassReverse /share &lt;/SPAN&gt;&lt;A href="http://127.0.0.1:8181/share" rel="nofollow noopener noreferrer"&gt;http://127.0.0.1:8181/share&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;/VirtualHost&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Error:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt; 2014-10-06 02:07:24,839&amp;nbsp; ERROR [alfresco.web.site] [http-bio-8181-exec-2] javax.servlet.ServletException: Possible CSRF attack noted when asserting referer header '&lt;/SPAN&gt;&lt;A href="http://XXX.XXX.XXX.XX/share/page/" rel="nofollow noopener noreferrer"&gt;http://XXX.XXX.XXX.XX/share/page/&lt;/A&gt;&lt;SPAN&gt;'. Request: POST /share/page/dologin, FAILED TEST: Assert referer POST /share/page/dologin :: referer: '&lt;/SPAN&gt;&lt;A href="http://XXX.XXX.XXX.XX/share/page/" rel="nofollow noopener noreferrer"&gt;http://XXX.XXX.XXX.XX/share/page/&lt;/A&gt;&lt;SPAN&gt;' vs server &amp;amp; context: &lt;/SPAN&gt;&lt;A href="http://127.0.0.1:8181/" rel="nofollow noopener noreferrer"&gt;http://127.0.0.1:8181/&lt;/A&gt;&lt;SPAN&gt; (string) or &lt;/SPAN&gt;&lt;A href="http://localhost:8181" rel="nofollow noopener noreferrer"&gt;http://localhost:8181&lt;/A&gt;&lt;SPAN&gt; (regexp)han&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If I try access directly it's work but if I try access behind httpd show me the error above.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Someone have idea about how I can solve this problem?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 06 Oct 2014 10:19:29 GMT</pubDate>
    <dc:creator>rodrigorapozo</dc:creator>
    <dc:date>2014-10-06T10:19:29Z</dc:date>
    <item>
      <title>4.2.f  Possible CSRF attack noted when asserting referer header</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/4-2-f-possible-csrf-attack-noted-when-asserting-referer-header/m-p/305640#M258770</link>
      <description>Hello everyone,I have a problem after put my alfresco behind apache httpd:&amp;lt;VirtualHost *:80&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProxyPass /share http://127.0.0.1:8181/share&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ProxyPassReverse /share http://127.0.0.1:8181/share&amp;lt;/VirtualHost&amp;gt;Error: 2014-10-06 02:07:24,839&amp;nbsp; ERROR [alfresco.web.site] [http-bio-8181-</description>
      <pubDate>Mon, 06 Oct 2014 10:19:29 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/4-2-f-possible-csrf-attack-noted-when-asserting-referer-header/m-p/305640#M258770</guid>
      <dc:creator>rodrigorapozo</dc:creator>
      <dc:date>2014-10-06T10:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: 4.2.f  Possible CSRF attack noted when asserting referer header</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/4-2-f-possible-csrf-attack-noted-when-asserting-referer-header/m-p/305641#M258771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Have you tried to include &lt;/SPAN&gt;&lt;A href="http://httpd.apache.org/docs/2.2/mod/mod_proxy.html#proxypreservehost" rel="nofollow noopener noreferrer"&gt;http://httpd.apache.org/docs/2.2/mod/mod_proxy.html#proxypreservehost&lt;/A&gt;&lt;SPAN&gt; directive?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You can also proxy using AJP protocol.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Oct 2014 12:48:30 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/4-2-f-possible-csrf-attack-noted-when-asserting-referer-header/m-p/305641#M258771</guid>
      <dc:creator>angelborroy</dc:creator>
      <dc:date>2014-10-06T12:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: 4.2.f  Possible CSRF attack noted when asserting referer header</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/4-2-f-possible-csrf-attack-noted-when-asserting-referer-header/m-p/305642#M258772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi, &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;AJP is not capable of dealing with heavy load. So if you have much traffic, try to go for a Filter instead.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Best,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Tim&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jul 2016 13:08:00 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/4-2-f-possible-csrf-attack-noted-when-asserting-referer-header/m-p/305642#M258772</guid>
      <dc:creator>timharder</dc:creator>
      <dc:date>2016-07-13T13:08:00Z</dc:date>
    </item>
  </channel>
</rss>

