Forum Discussion
Lance_99151
Nimbostratus
Sep 06, 2012ASM - 200001067 Attack Signature
Struggling to find info on this AS and wanted to know if it was safe to disable it on a parameter or if there is a better approach. I am on 10.2
thanks
Lance
3 Replies
- Lance_99151
Nimbostratus
Signature ID 200001067 - mocha (Parameter)
Blocking Mask
Learn - Yes; Alarm - Yes; Block - Yes
Details
Context: Parameter
Parameter Level: Global
Wildcard Parameter Name: *
Actual Parameter Name: searchTerm
Parameter Value: Mocha
Detected Keywords: searchTerm=Mocha - Torti
Cirrus
I recommend to disable this, allways. There exists a lot of possible parameter, like cities, email address, name, which can contain the substring mocha. - Cory_50405
Noctilucent
We've disabled this attack signature for parameters across several security policies. The accuracy of the signature is low, so the false positive rate is high. I wouldn't necessarily disable it for every parameter or on every policy, but just do so on policies/parameters that are problematic.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
