EPrints Technical Mailing List Archive

Message: #08022


< Previous (by date) | Next (by date) > | < Previous (in thread) | Next (in thread) > | Messages - Most Recent First | Threads - Most Recent First

Re: [EP-tech] CSRF


Hi Newman,

It's a new installation and the file exist under this path (EPRINTS_PATH /archives/ ARCHIVE_NAME /cfg/cfg.d) but our security team is doing a vulnerability scan using Acunetix and it's giving CSRF Token missing error on all pages.

Is there a way we can verify that CSRF token are being applied?

 

 

From: Newman D.R. [mailto:drn@ecs.soton.ac.uk]
Sent: Thursday, November 07, 2019 3:13 PM
To: eprints-tech@ecs.soton.ac.uk; Maher Abdellatif Ahmad Qahwash
Subject: Re: [EP-tech] CSRF

 

تحذير: هذه الرسالة مرسلة من خارج الجامعة. لا تفتح أي مرفق أو رابط ما لم تكن متأكداً من أنه آمن
Warning: This mail has been sent from outside KFUPM. Do not open links or attachments unless you are sure they are safe.
____________________________________________________________

Hi Maher,

This depends if you have just created a new repository/archive or if you have upgraded to 3.4.1 for an existing archive.  For the latter you will need to manually copy EPRINTS_PATH/lib/defaultcfg_zero/cfg.d/csrf_protection.pl to you archive (i.e.  EPRINTS_PATH/archives/ARCHIVE_NAME/cfg.d/csrf_protection.pl).  Otherwise csrf_protection.pl should have automatically added to you archive on creation.  Either way it is best you change the csrf_token_salt config variable to something else.  Generating a suitable token salt can be done using OpenSSL:

openssl rand -base64 8

8 characters should be more than sufficient, as the current time is also used in generating each token.  Using the default token salt gives you improved security but is not ideal as a determined hacker could work out valid tokens they could use.

Regards

David Newman

On 07/11/2019 11:54, Maher Abdellatif Ahmad Qahwash via Eprints-tech wrote:

Hi

 

We are running eprints 3.4.1 and would like know if CSRF is enabled by default or we need to enable it in the configuration?

 

Thanks

Maher



*** Options: http://mailman.ecs.soton.ac.uk/mailman/listinfo/eprints-tech
*** Archive: http://www.eprints.org/tech.php/
*** EPrints community wiki: http://wiki.eprints.org/
*** EPrints developers Forum: http://forum.eprints.org/

  • Follow-Ups: