Log in

View Full Version : Missing or Invalid Security Token detected spam


steven s
06-19-2008, 09:53 PM
These is what is being return to me via Andrea's mod
https://vborg.vbsupport.ru/showthread.php?t=177017

They are not being posted, but how are they able to begin to post?
Are they replying as a guest?

It also looks like they are trying to send a PM at the same time.


Missing or Invalid Security Token detected.

Script Call Backtrace
=====================
#0 ../forum/includes/functions.php line 2592: eval()
#1 ../forum/includes/init.php line 417: fetch_error(security_token_missing,ltr,sendmessage .php)
#2 ../forum/global.php line 20: require_once(../forum/includes/init.php)
#3 ../forum/newreply.php line 82: require_once(../forum/global.php)

POST Variables
==============
Array
(
[title] => In a crowded courtroom
[message] => In a crowded courtroom in wow gold ( spam url) Mississippi, a jury returns wow gold ( spam url)

a shocking verdict against wow power leveling ( ==spam url == ) a chemical company accused of dumping toxic waste into a small town's water

supply, causing the worst “cancer cluster” in history. The company wow power leveling ( spam url/) appeals to the Mississippi Supreme Court,

whose nine justices will one day either approve the verdict wow power leveling ( spam url /) or reverse it.weiwei1978123
[wysiwyg] => 1
[iconid] => 1
[s] =>
[do] => postreply
[t] => 21753
[p] => 170155
[posthash] => 2f9d9d501126996ed71103b06498354c
[poststarttime] => 1213904593
[loggedinuser] => 5974
[multiquoteempty] =>
[sbutton] =>
[signature] => 1
[parseurl] => 1
[emailupdate] => 9999
[rating] => 5
[threadid] => 21753
[postid] => 170155
[securitytoken] =>
)

Request URI
===========
/forum/newreply.php?do=postreply&t=21753

Dismounted
06-20-2008, 10:24 AM
Make sure your templates (in this case, newreply?) have the security token embedded.

steven s
06-20-2008, 12:43 PM
So is it possible that these spammers are actually registered?
Normally their keywords are caught by an addon and thrown into moderation.
These don't get that far.

Opserty
06-20-2008, 12:46 PM
This looks like the userid of the whoever is trying to post: [loggedinuser] => 5974

steven s
06-20-2008, 02:56 PM
This looks like the userid of the whoever is trying to post: [loggedinuser] => 5974
Excellent. I hadn't noticed the user id number.
I checked and sure enough, he is registered. Odd that none of his posts have gone through.
At least this gave me time to ban him.