Mar 27, 2026 - For details about updated CVE-2025-53521 (BIG-IP APM vulnerability), refer to K000156741.

Forum Discussion

Lance_99151's avatar
Lance_99151
Icon for Nimbostratus rankNimbostratus
Sep 06, 2012

ASM - 200001067 Attack Signature

Struggling to find info on this AS and wanted to know if it was safe to disable it on a parameter or if there is a better approach. I am on 10.2

 

thanks

 

Lance

 

 

3 Replies

  • Signature ID 200001067 - mocha (Parameter)

     

    Blocking Mask

     

    Learn - Yes; Alarm - Yes; Block - Yes

     

    Details

     

    Context: Parameter

     

    Parameter Level: Global

     

    Wildcard Parameter Name: *

     

    Actual Parameter Name: searchTerm

     

    Parameter Value: Mocha

     

    Detected Keywords: searchTerm=Mocha

     

  • I recommend to disable this, allways. There exists a lot of possible parameter, like cities, email address, name, which can contain the substring mocha.
  • We've disabled this attack signature for parameters across several security policies. The accuracy of the signature is low, so the false positive rate is high. I wouldn't necessarily disable it for every parameter or on every policy, but just do so on policies/parameters that are problematic.