Bitcoin Forum
May 05, 2024, 01:32:40 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: localbitcoins.com - csrf error  (Read 1945 times)
tvbcof (OP)
Legendary
*
Offline Offline

Activity: 4592
Merit: 1276


View Profile
August 13, 2013, 09:41:55 PM
 #1


I thought I'd get an account with 'localbitcoins.com' even though transactions of the size I'm interested in don't seem that common.  Upon trying to set up an account, I get the following error:

  ---
  Forbidden (403)
  CSRF verification failed. Request aborted.
  More information is available with DEBUG=True.
  ---

In a search of bitcointalk.org, I only see one reference in the newbies section from someone else noticing the phenomenon, and no response.

Before I research the potential issues (if I even bother), I just wondered if others might have noticed the same behavior.

I am running on one of my more secure machines.  FreeBSD with Chromium built from source: Version 25.0.1364.97 (183676)  I am also on a satellite connection.  I am not interested in setting security ignore overrides unless and until I understand fairly completely why such behavior occurs, and this is particularly true of security certificate related issues in Bitcoin-land.


sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
1714872760
Hero Member
*
Offline Offline

Posts: 1714872760

View Profile Personal Message (Offline)

Ignore
1714872760
Reply with quote  #2

1714872760
Report to moderator
1714872760
Hero Member
*
Offline Offline

Posts: 1714872760

View Profile Personal Message (Offline)

Ignore
1714872760
Reply with quote  #2

1714872760
Report to moderator
1714872760
Hero Member
*
Offline Offline

Posts: 1714872760

View Profile Personal Message (Offline)

Ignore
1714872760
Reply with quote  #2

1714872760
Report to moderator
"If you don't want people to know you're a scumbag then don't be a scumbag." -- margaritahuyan
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714872760
Hero Member
*
Offline Offline

Posts: 1714872760

View Profile Personal Message (Offline)

Ignore
1714872760
Reply with quote  #2

1714872760
Report to moderator
Kris
Donator
Hero Member
*
Offline Offline

Activity: 640
Merit: 500


View Profile
August 14, 2013, 12:42:15 AM
 #2

I am thinking it may be session related. If the CSRF set client side does not match up with the CSRF server side, it would not allow you to complete the request.
However what might have caused this problem I would not know, I can only speculate.

1. No javascript enabled in your browser.
2. Browser not able to set cookies/session
3. A delay in connection, so the CSRF manage to timeout.
4. All of the above, or anything in between.
tvbcof (OP)
Legendary
*
Offline Offline

Activity: 4592
Merit: 1276


View Profile
August 14, 2013, 07:35:02 AM
 #3

Hey Kris, thanks for the info.

I doubt that I will find counter-parties interested in the volumes I want on localbitcoins anyway so I probably won't even diagnose things further.

Chromium is a more limited browser than Chrome and leaves out some non open-source stuff compiled into Chrome (which is some of the reason I'm more comfortable using it for more sensitive work in fact.)  This could be at the root of the issue I'm seeing, or it could be some session defect.  Or it could be a genuine MITM type thing I suppose.  Who knows.  I'll just log it away as a point of interest.


sig spam anywhere and self-moderated threads on the pol&soc board are for losers.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!