We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 12410
    • 353 Posts
    Hi Guys,
    Getting CSRF_TOKEN syntax injected to my url in Modx Revo 2.2.14 when I click on a clickable image.
    www.mysite.com/myresiurce/?CSRF_TOKEN=45a26b788ca5b4096f73bd3ad3f6c18a14daeb96


    Any idea what this is and how to disable?
    Thanks

    Ubuntu 14.04
    PHP Version 5.5.9-1ubuntu4.1
    Apache/2.4.7 (Ubuntu)
    mysql 5.5.37
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      What plugins or image-processing snippets are you using?
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 12410
        • 353 Posts
        Hi,
        I'm using pthumb which relies on Resizer and PhPThumb. Seems to appear when I have multiple tabs of the same webpage open
        Thanks
          • 12410
          • 353 Posts
          Just opened the manager in chrome and my url has it too.

          www.mysite.com/manager/?a=70&CSRF_TOKEN=73afd3866fc2d5e8669037c9cfd98c3b9792ae3e
            • 3749
            • 24,544 Posts
            Usually, the CSRF_TOKEN is added by some add-on for added security. If you haven't installed a plugin to do it, maybe your host has.
              Did I help you? Buy me a beer
              Get my Book: MODX:The Official Guide
              MODX info for everyone: http://bobsguides.com/modx.html
              My MODX Extras
              Bob's Guides is now hosted at A2 MODX Hosting
              • 12410
              • 353 Posts
              Hi, any ideas what extra may cause it ? I configured the lamp server myself and there's no mod_security or similar involved. It's the first time I've seen it happen on a revo site
                • 12410
                • 353 Posts
                Like should I be worried about malicious script in some extra I downloaded or my server being hacked.
                My host, Linode got back with:


                Hello,

                Thank you for contacting Linode Support! While we would be happy to help we don't add any CSRF tokens and we wouldn't know why they are being added to your website. That being said you can read about CSRF at

                https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)

                Please let us know if you have any questions or need anything else!

                .... The content of the link on csrf is conceding.
                Any ideas guys?
                  • 3749
                  • 24,544 Posts
                  I wonder if it could be a browser add-on. Have you tried it with other browsers?

                  If it occurs in all browsers, I'd start disabling plugins one-by-one to see if one of them is doing it.
                    Did I help you? Buy me a beer
                    Get my Book: MODX:The Official Guide
                    MODX info for everyone: http://bobsguides.com/modx.html
                    My MODX Extras
                    Bob's Guides is now hosted at A2 MODX Hosting