It will result in a captcha (that’s ok), but the forum system is not able to post this posting anymore (error: “No post selected”), so it seems that CloudFlare is not transferring all required information over the captcha anymore.
This was possible all the time, but something changed during the last days. Does anyone know what or which rule I might try to disable to get this working again?
I did not change anything on the forum (or website or server), but realized that CloudFlare added some new rules. So it’s just a guess that CloudFlare might have added some new security features that affect my forum system somehow.
I did some more testing and noticed that the problem occurs when my users are getting a challenge/captcha AND try to post a reply with specific URLs in it. In that case some information are not beeing “transferred” correctly from the user through the Captcha and back to my website (something seems to be missing!?).
I disabled all OWASP rules regarding “IE XSS Filters - Attack Detected” and now the users are not getting a challenge anymore and can therefor post again. I know that’s not the real solution, but for the moment it works.