Forum Discussion
imac_105647
Nimbostratus
Jun 23, 2010Application firewalling quandary
This problem is not strictly limited to ASM, but is a more general question:
I am seeing lots of end users type things that throw an exception on the ASM (it's not in blocking mode so I'm just working through these things), for example a user hits the shift key when typing a postcode so instead of typing FT3 5AC they type FT3 percentage signAC, or they forget to shift when typing an email address and we get test'test.com, I've even had someone type -- into a date field.
So my quandary is this: I can disable these exceptions and allow the application to deal with these typos, which it does much more gracefully than the ASM can, but I have to be sure the app does it's validation correctly so that, if I allow these characters through, the app is not going to be compromised. Or I allow ASM to block these typos and potentially confuse the end user (there seems to be no way for the ASM to do anything graceful here in prompting the user as to what they have done wrong). I obviously want to block the bad guys, but I want to keep the customer who has made a typo without significantly weakening the ASM policy. How do you guys deal with situations like this?
- hoolio
Cirrostratus
Hi Ian, - imac_105647
Nimbostratus
Hi Aaron,
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects