Support

Admin Tools

#27067 Is it possible to test if CSRF shield?

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Friday, 10 March 2017 17:17 CST

hollai
 I wonder if it is possible to test if the CSRF shield.

I have a website with a contact us form. Instead of CAPTCHA, we use the AdmintTools CSRF shield -- CSRF shield advanced setting. However the website is getting spam submissions regularly.

I wonder if the CSRF shield works on the website.
Is it possible to test it?
Is it possible that the CSFR shield conflicts with another extension of the given website?
The address of the website is baysidefurniture.com

I cannot preclude the possibility that the spam submissions are manual spams -- it would be good to know whether the CSRF shield works properly in the given website.

tampe125
Akeeba Staff
Hello,

the CSRF feature injects a field that is not visible inside the form (it's not an "hidden" input type, it's simply moved out of the screen browser using inline css styles).
To test such feature, you have to inspect the source using your browser console and assign it a value. Most bot will fill it while users will leave it empty: if such field is filled, Admin Tools will block the request.

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!