Forum Discussion
Analyzing F5 OWASP rule matches
I am seeing lots of requests that match the following rules:
rule_XSS_script_tag__Parameter__AllQueryArguments_Body
rule_div_tag__behavior__Parameter__AllQueryArguments_Body
rule_chmod_execution_attempt__Parameter__AllQueryArguments_Body
rule_SQL_INJ_end_quote_UNION__Parameter__AllQueryArguments_Body
How can I determine why the requests are matching?
#F5 rules for AWS WAF
- JRahmAdmin
Do you have source documentation for what you're referencing? Any details will be helpful, I'll see if I can track this down for you internally.
- JRahmAdmin
And you've setup the steps on pages 12-15 in the getting started guide: https://pages.awscloud.com/rs/112-TZM-766/images/F5_OWASP_Getting%20Started%20Guide.pdf?
I'm asking around internally, will let you know what I find.
- tboemkerNimbostratus
As much as possible, yes. (The doc appears to have been written for an older version of the WAF Console.) I do not see request bodies in the logs, and Amazon Support said that they don't log request bodies.
- JRahmAdmin
ok thanks for the info, I'll keep you posted.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com