[horde] We cannot verify that this request was really sent by you.

Steve Devine sd at msu.edu
Tue Oct 14 20:20:37 UTC 2008


We have one user who is consistently getting this error.
"We cannot verify that this request was really sent by you. It could  
be a malicious request."  He will get it 3 or 4 times a day most often  
right after he has logged in but not always.

I think this error comes from "function checkRequestToken" in imp/lib/IMP.php
Whats the purpose of this? I see it gets called from folders.php, mailbox.php
and message.php
It's description is "check if a token for form is valid" .. so is this  
supposed to check for cross-site scripting or some other trickery?
Any suggestions on trouble shooting this?
We are running horde-webmail-1.1.3
Thanks



Steve Devine
Email & Storage
Academic Technical Services
Michigan State University

313 Computer Center
East Lansing, MI 48824-1042
1-517-432-7327




More information about the horde mailing list