|
Joined: Jun 2006
Posts: 996 Likes: 24
Old Hand
|
Old Hand
Joined: Jun 2006
Posts: 996 Likes: 24 |
Hello, I have had Cloudflare installed for quiet a long time. Cloudflare checks browsers etc and gets them verified. A problem has started to occur when members and my self use the attachment manager It first verifies and should go back to attachment manager but it doesn't See below images it shows top images briefly and then the middle and then opens the forum start page in the box.. very strange, meaning its not possible to use the manager. It's not always but in many many cases and for many members. I would be very grateful for any ideas. here is more info from one memberMorgan,
The three separate screenshots combined on the attached jpg (captured in Win10 by hitting the PrintScreen button and copying the images to Photoshop to combine) are typical.
Cloudflare doesn't intrude after the first image is successfully uploaded to a post. But, when I try to upload the first image to a new post I get the screen at the top of the attached. After some number of seconds I either get the second screen, or a similar one that asks me to check a box to prove I'm human. After some additional number of seconds, I'm either allowed to upload the image as if Cloudflare hadn't ever been there, or about 30% of the time I get the third screen.
For the past couple of months, when I get the third screen I could close it and try again to upload the image. When that happens, it goes through the first two screens again and usually then allows me to upload the photograph. However, starting this afternoon, I can never get past the third screen despite a half-dozen tries, and making those tries several hours apart.
In the past, the third screen was "dead", in that the slider at the right wouldn't move. However, now I've found the slider does move, and that third screen is just a small version of the Britbike site, i.e. I can access all the forums and posts in it. That is, instead of Cloudflare taking me to the attachments screen where I can upload photographs, it takes me to the main site.
I even tried to upload a second time through the site in the third screen, but it took me in a loop and I ended up with two small screens embedded in each other.
Charles
Last edited by Morgan; 02/15/2024 9:18 AM.
|
|
|
|
Joined: Jun 2006
Posts: 16,348 Likes: 124
|
Joined: Jun 2006
Posts: 16,348 Likes: 124 |
I use Cloudflare on every one of my sites, so if I'm understanding the user is: 1. Attaching an image to a post with the full size editor with drag and drop 2. Attaching a second image which is having some sort of error?
As Cloudflare is a third party service there isn't really much we can do, but if we can replicate an issue we might be able to find a setting...
|
|
|
|
Joined: Jun 2006
Posts: 996 Likes: 24
Old Hand
|
Old Hand
Joined: Jun 2006
Posts: 996 Likes: 24 |
Gizmo I sent you a couple videos on messenger to show it in real time but here is photos of it Here is how it can look Full editor, attachment manager,select image Coosing image cloudflare verifying that you are human shows in box ict changes to verification ok then forum startpage comes up box window No files are being attached.... Hope this helpes. Its a pain when our members cannot post
|
|
|
|
Joined: Dec 2003
Posts: 6,621 Likes: 84
|
Joined: Dec 2003
Posts: 6,621 Likes: 84 |
I have never used cloudflare captcha feature. The first thing I would do is turn off cloudflare for a test There are a lot of issues with it but at least you can turn it off to rule out one variable.
Blue Man Group There is no such thing as stupid questions. Just stupid answers
|
|
|
|
Joined: Jun 2006
Posts: 996 Likes: 24
Old Hand
|
Old Hand
Joined: Jun 2006
Posts: 996 Likes: 24 |
There are lots of security involved with Cloudflare. It's a whole package of services that used to work fine. I set a rule to skip one IP address and it started to work for him. I can't figure out how to proceed. If I found out what is causing the issues with UBBC then it would be easier to search.
|
|
|
|
Joined: Jun 2006
Posts: 996 Likes: 24
Old Hand
|
Old Hand
Joined: Jun 2006
Posts: 996 Likes: 24 |
As far as I understand, everyone on my forum is accepted by Coudflare, No one is blocked to open the pages but it's the attachment feature that doesn't not work.
|
|
|
|
Joined: Jun 2006
Posts: 996 Likes: 24
Old Hand
|
Old Hand
Joined: Jun 2006
Posts: 996 Likes: 24 |
more info poll manager works fine
|
|
|
|
Joined: Dec 2003
Posts: 6,621 Likes: 84
|
Joined: Dec 2003
Posts: 6,621 Likes: 84 |
Turn off cloudflare and test. It is a simple check box on the landing page next to the check box for I am having a ddos attack. It is there just for this type of scenario to test cloudflare. This will confirm or rule out cloudflare is the issue.
If attachments still don't work it is on your host or UBB side.
If attachments do work then try turning cloudflare back on and find what they call challenge setting turn it off and see if attachments work. If they do then experiment with the different challenge levels.
Blue Man Group There is no such thing as stupid questions. Just stupid answers
|
|
|
|
Joined: Jun 2006
Posts: 996 Likes: 24
Old Hand
|
Old Hand
Joined: Jun 2006
Posts: 996 Likes: 24 |
Ruben, I tested the checkbox beside a ddos attack checkbox, nothing happened, it is the Development Mode Temporarily bypass our cache. See changes to your origin server in realtime checkbox.
|
|
|
|
Joined: Jun 2006
Posts: 996 Likes: 24
Old Hand
|
Old Hand
Joined: Jun 2006
Posts: 996 Likes: 24 |
I have now created a topic at the Cloudflare community, let see if I get any respond to it https://community.cloudflare.com/t/cloudflare-human-verification-corrupts-uploading-files/617840Also started a support ticket at my host Actually It took three attemts to start the ticket as they seemed to have same issue as I have. I submitted the ticket and the verification notice came and the verificating succes came and then back to the empty form... I didn't believe my eyers second attempt same result third attempt was a success so now my ticket is up there. Anyway I'm all ears for ideas, If Gizmo or Isaac or Ruben would be interested you are welcome to login and test my forum. It's frustrating 😬
|
|
|
|
Joined: Jun 2006
Posts: 996 Likes: 24
Old Hand
|
Old Hand
Joined: Jun 2006
Posts: 996 Likes: 24 |
some good news
I started to read all the cloudflare security event logs. Found that I myself caused a manage challenge to happen, reading the logs I found 11 issues that was connected to Cloudflare OWASP Core Ruleset I simply turned off the Cloudflare OWASP Core Ruleset and it started to work for me at least..
The drag and drop started to work again too... fingers crossed. Now i need to find out what OWASP does.. Thanks for listening in...
|
|
|
|
Joined: Jun 2006
Posts: 996 Likes: 24
Old Hand
|
Old Hand
Joined: Jun 2006
Posts: 996 Likes: 24 |
Update, I enabled OWASP again but reset rules to default and it still work. Both select and drag and drop ✅🙏
Last edited by Morgan; 02/20/2024 8:40 AM.
|
|
|
|
Joined: Dec 2003
Posts: 6,621 Likes: 84
|
Joined: Dec 2003
Posts: 6,621 Likes: 84 |
There you go. I have not used the default turn off for cloudflare in a while so maybe they removed or moved the option.. I will look for it when I get a chance.
Blue Man Group There is no such thing as stupid questions. Just stupid answers
|
|
|
|
Joined: Jun 2006
Posts: 16,348 Likes: 124
|
Joined: Jun 2006
Posts: 16,348 Likes: 124 |
I was really at a loss as UBBthreads is a simple PHP script that should "just work" on most standard systems, but Cloudflare isn't a normal standalone system so it's completely out of the scope of forum support, there are just too many rules that can do too many things...
Initially I was going to have you see if they had a log of actions they were performing since the issues looked like settings affecting their system (since the forum goes through their system before presenting to the user).
Honestly I'd never even heard of their OWASP rules, I just use them as a firewall.
|
|
|
|
Joined: Jun 2006
Posts: 996 Likes: 24
Old Hand
|
Old Hand
Joined: Jun 2006
Posts: 996 Likes: 24 |
UBBthreads is old and a lot has been developed since then that may or may not affect the behavior of our forums. Software comes and goes system becomes obsolete or depreciated. Even though its not a direct forum script issue. Just addressing that our forums are affected and communicating around it helpes. What Gizmo and Ruben did guided me bit by bit towards the solution. it steered me towards the logs and eventually I found my own logs and from that I did what Ruben suggested I disabled not exactly what he said asked for but the OWASP that I found in the logs.
So from my point of view I'm satisfied and possible if someone else looks for similar info he can always search for it here now when its been documented.
If you go to Cloudflare > Security > WAF > Managed rules - you can read about it.
Cheers
|
|
|
|
Joined: Jun 2006
Posts: 16,348 Likes: 124
|
Joined: Jun 2006
Posts: 16,348 Likes: 124 |
Out of curiosity, what page did you end up finding appropriate logs on the OWASP issue on Cloudflare?
|
|
|
|
Joined: Jun 2006
Posts: 996 Likes: 24
Old Hand
|
Old Hand
Joined: Jun 2006
Posts: 996 Likes: 24 |
Cloudflare > Security > Event > I set the firewalls to 30 min and scrolled to the bottom where the logs are
Then I open another window and open my forum where I tried to attach an image. I knew it would trigger a log result.
Then back at cloudflare I renew the page and noticed a log with my IP address and also it read Sweden as country where I live. I then could see info and also could click to open more logs it was total 11 OWASP logs regarding a "managed challenge" not a block.
Hope this helps
|
|
|
|
Joined: Jun 2006
Posts: 996 Likes: 24
Old Hand
|
Old Hand
Joined: Jun 2006
Posts: 996 Likes: 24 |
|
|
|
1 members (Ruben),
574
guests, and
101
robots. |
Key:
Admin,
Global Mod,
Mod
|
|
|
|