Welcome, Guest. Please login or register.
Did you miss your activation email?
May 26, 2012, 05:00:20 PM

Login with username, password and session length
Search:     Advanced search
Wollen Sie dem WebsiteBaker Team beitreten?
Nähere Informationen finden Sie unter hier und auf unserer neuen Webseite.
155544 Posts in 21714 Topics by 7736 Members
Latest Member: chris85
* Home Help Search Login Register
Pages: 1 2 3 [4]   Go Down
Print
Author Topic: Security offense!! Access denied!  (Read 7434 times)
BlackBird
AddOn Development
*
Offline Offline

Posts: 2069



WWW
« Reply #75 on: June 10, 2011, 02:05:51 PM »

I think its because some modules open stuff in a new popup window or do some other kind of transaction .

I am still having the problem with ALL forms in the BE. I tried to work with it with IE instead of FF - same problem. So in fact it IS unusable here. To be able to go on with my module tests, I had to fake all DB entries and access files. So don't say unusable is a too hard word. wink
Logged

Alle großen Veränderungen beginnen im Kleinen
BlackBird
AddOn Development
*
Offline Offline

Posts: 2069



WWW
« Reply #76 on: June 10, 2011, 02:11:09 PM »

Found that the problem was caused by an older BE theme. Seems the SecureForm.php requires changes in the BE Themes, too.
Logged

Alle großen Veränderungen beginnen im Kleinen
Luisehahne
Board Member
Development Team
*****
Offline Offline

Posts: 3147



WWW
« Reply #77 on: June 10, 2011, 02:13:51 PM »

You can check it, the BE Theme need a variable like {FTAN} after the form tag.

Dietmar
Logged

We are human beings - and nobody is perfect at all.
ruebenwurzel
WebsiteBaker Org e.V.

Offline Offline

Posts: 7973



WWW
« Reply #78 on: June 10, 2011, 05:50:50 PM »

Hello,

tested it over and over again on all sites, with updeted (but non patched) versions and also did some new clean installs and cannot reproduce this error message.

But maybe biancas hint seems to be the solution. I always work with the default Backend "wb_theme". Didn't use other themes because they maybe look better but i always run in problems with them.

Matthias
Logged
Argos
Moderator
**
Offline Offline

Posts: 2161


WWW
« Reply #79 on: June 10, 2011, 10:22:30 PM »

Strange. I just tested a brand new, clean latest RC6 and had no problems (I use Argos theme of course). That is, as long as didn't have multiple tabs open. I just found out by the way that you can use multiple tabs with a simple little trick anyway (not the file hack I posted earlier).

I am disappointed though that the picture option stefek added is not yet added to the core News module. It is an essential option in my opinion.
Logged

Jurgen Nijhuis
Argos Media
Heiloo, The Netherlands
WB Showcase: http://www.mywebsitebaker.com/pages/showcase.php?v&category_id=1242&count=30
----------------------------------------------------------------
Please don't request personal support, use the forums!
NorHei
Forum administrator
*****
Offline Offline

Posts: 485



WWW
« Reply #80 on: June 10, 2011, 11:03:39 PM »

You can go and open a second tab, change a few things go back and then reload the page to have its FTAN refresh. If you try this whith more than 2 tabs you have to keep track of the last one you refreshed .  Try to explain that to your Client   grin

For me the atempt to install that news thingy simply lead to a bunch of error messages and nothing else.
I dont think its a good idea to put something like that even into AMASP.
Open a module thread , let pepole test it , fix all Problems , put it on AMASP.
And then after a while its ok to discuss about adding it to the Core .

I dont even expect the patch go into the core as it is. If Devs ever decide to add this patch , it needs a complete rework as its mixed coding style and some redundant functions .
Logged

It is easier to change the specification to fit the program than vice versa.
Stefek
WebsiteBaker Org e.V.

Offline Offline

Posts: 4884



« Reply #81 on: June 10, 2011, 11:33:57 PM »

For me the atempt to install that news thingy simply lead to a bunch of error messages and nothing else.
I dont think its a good idea to put something like that even into AMASP.
As I remeber the problems you ran into where the same with a untoutched news module.
There shouldn't be any problems with my changes what so ever, despite those already are part of the module.

Stefek
Logged

"In a time of universal deceit, telling the truth becomes a revolutionary act."
- George Orwell, Nineteen eighty-four (1984)
NorHei
Forum administrator
*****
Offline Offline

Posts: 485



WWW
« Reply #82 on: June 11, 2011, 04:45:29 PM »

Just want to mention, this is the wrong thread for news  wink
Logged

It is easier to change the specification to fit the program than vice versa.
Luisehahne
Board Member
Development Team
*****
Offline Offline

Posts: 3147



WWW
« Reply #83 on: June 11, 2011, 05:41:36 PM »

INFO!
We are working for a solution, only one FTan for each page, so all sections (module) have the same one.

The actually working is that each sections has his own FTAN and run in security error.

Ok that solved not the multitab problem, but many others.

Dietmar
Logged

We are human beings - and nobody is perfect at all.
NorHei
Forum administrator
*****
Offline Offline

Posts: 485



WWW
« Reply #84 on: June 11, 2011, 10:31:30 PM »

Jep, confirmed.
The erratic behavior seems to have  its origin in multiple section forms, that generate a FTAN for each section of the form. But only the last FTAN generated is valid, all other sections will malfunction.

Another problem i see is having javascript open a secondary form, for example to upload an image.
If the secondary form is send the main form is no longer valid. 
Logged

It is easier to change the specification to fit the program than vice versa.
babsy

Offline Offline

Posts: 322


« Reply #85 on: August 09, 2011, 12:40:15 PM »

hi Smiley i just installed a new website with this 2.8.2 version, but i can´t make an page?
i just get the message:

Security offense!! Access denied!

i have followed the installed guide, and everything worked fine, and i can´t seem to find any information about how to get pass this message, and get started to make pages?

Logged
Argos
Moderator
**
Offline Offline

Posts: 2161


WWW
« Reply #86 on: August 09, 2011, 12:47:35 PM »

Untill someone comes wih a solution, you can disable the security function (FTAN) in the admin settings if you like, and see if that helps.
Logged

Jurgen Nijhuis
Argos Media
Heiloo, The Netherlands
WB Showcase: http://www.mywebsitebaker.com/pages/showcase.php?v&category_id=1242&count=30
----------------------------------------------------------------
Please don't request personal support, use the forums!
babsy

Offline Offline

Posts: 322


« Reply #87 on: August 09, 2011, 01:09:32 PM »

Actually, i can´t do anything in the backend, without getting the message:
Security offense!! Access denied!

i can´t make any changes in the admin security Sad
Logged
maverik

Offline Offline

Posts: 1568



WWW
« Reply #88 on: August 09, 2011, 01:11:55 PM »

1) say sleep well for 24 hours to the browser you installed wb  grin
2) take another browser and go to admin tools > secure form switcher and activate multitab
3) save
4) for now on all should work fine >> i hope
Logged

Signatur wird geladen...
babsy

Offline Offline

Posts: 322


« Reply #89 on: August 09, 2011, 01:20:09 PM »

Hi Smiley yes.. i will do that.. and i see it workes ok in IE Smiley
Logged
NorHei
Forum administrator
*****
Offline Offline

Posts: 485



WWW
« Reply #90 on: August 09, 2011, 01:27:19 PM »

If might although help if you close all tabs , clear cache and cookies and restart your browser.
Logged

It is easier to change the specification to fit the program than vice versa.
ufferichter

Offline Offline

Posts: 36


WWW
« Reply #91 on: August 28, 2011, 08:19:10 PM »

I have read about the Security offense!! Access denied!and tryed everything now, i cant update from Version 2.8.1 without this problem, i dont know what to do, i go back to this version every time
Logged

Regards Uffe

websitebaker.dk
ruebenwurzel
WebsiteBaker Org e.V.

Offline Offline

Posts: 7973



WWW
« Reply #92 on: August 29, 2011, 06:25:39 AM »

@ufferichter

Wich errors you have exactely? You cannot update, means this the upgrade fails? Or did the upgrade work well and you got then error messages in the backend? Did you use a built in backend-theme or your own?

As more infos we get, the better we can help.

Matthias
Logged
ufferichter

Offline Offline

Posts: 36


WWW
« Reply #93 on: August 30, 2011, 12:38:20 PM »

I just overwrite with the new files in 2.8.2 and use the upgrade.php and i altso try to use the last upgrade to overwrite files, but no mater what i do Security offense!! Access denied everytime when i try to edit or save chances, så i go back to last stable version
Logged

Regards Uffe

websitebaker.dk
Pages: 1 2 3 [4]   Go Up
Print
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!