Forum Discussion
Dan_Markhasin_1
Nimbostratus
Oct 26, 2015Apply ASM attack signatures to URLs?
Hi,
Is it possible to apply ASM attack signatures detection to URLs? This is the scenario I am trying to solve:
1) Assume we have a RESTFul web service that returns user details given a use...
Dan_Markhasin_1
Nimbostratus
Oct 26, 2015Hi Tim,
The SQL Injection signatures are in fact enabled, and successfully block SQL injections if these come in the request body.
This is identified by ASM as a SQL Injection attack: POST to with a body that looks like: {"user":"' OR 1=1 --"}
This is not identified by ASM as a SQL Injection attack: GET to '%20OR%201=1%20--
Instead, ASM detects that the request has illegal characters in the URL - which is fine, but it means it is not applying attack signature validation to the URL itself...
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects