Forum Discussion
Albert_252822
Nimbostratus
Apr 20, 2016Adding parameters to a vulnerability
Hi all,
What do you think is the best method to add different parameters to a known vulnerability.
The scenario is that my vulnerability scanner detects an SQL Injection on the paramter "us...
mortoj_167568
Altocumulus
Apr 22, 2016That's a good question. I haven't configured a parameter using Data type but I took a look. It appears that when Data type - Integer is chosen, the only value(s) that can be entered for this type of parameter (using data-type -> Intger) are whole numbers. I do not believe Attack Signatures are checked against this type of parameter with the Data Type -> Integer selected.
My best guess is that there are no attack signature patterns that consist of strictly and only whole numbers.
My reference is ASM Configuration Guide 10.2. (Start on page 10 - 14 Configuring parameter characteristics for user-input parameters.....Integer is on page 10 - 18)
https://support.f5.com/content/kb/en-us/products/big-ip_asm/manuals/product/config_guide_asm_10_2_0/_jcr_content/pdfAttach/download/file.res/asm_config_guide_10_2.pdf
----Hope this helps----
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects