Forum Discussion
dburnett_103851
Nimbostratus
Dec 10, 20089.4.5 upgrade and HTTP Protocol Compliance
We currently have F5 Big IPs within a 'live' website environment and a 'pre-live' environment.
We have recently upgraded our pre-live environment from 9.4.3 to 9.4.5.
All...
dburnett_103851
Nimbostratus
Dec 16, 2008I've checked out our character set settings.
Whilst we have the carriage return and line feed characters disallowed at a global level we have a wildcard parameter of * which has both of them set as allowed, plus also a couple of other parameters such as a comments field, which has them allowed.
For information, the * wildcard had to be put in due to the number of dynamic parameters that are created by our web application.
Don't know if you can answer this or not but if we were to turn off the HTTP protocol compliance feature in order to rely on the character set restrictions (and the attack signatures) is the * wildcard parameter opening us up to HTTP Response Split attacks?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
