Forum Discussion

  • Signature ID 200001067 - mocha (Parameter)

     

    Blocking Mask

     

    Learn - Yes; Alarm - Yes; Block - Yes

     

    Details

     

    Context: Parameter

     

    Parameter Level: Global

     

    Wildcard Parameter Name: *

     

    Actual Parameter Name: searchTerm

     

    Parameter Value: Mocha

     

    Detected Keywords: searchTerm=Mocha

     

  • I recommend to disable this, allways. There exists a lot of possible parameter, like cities, email address, name, which can contain the substring mocha.
  • We've disabled this attack signature for parameters across several security policies. The accuracy of the signature is low, so the false positive rate is high. I wouldn't necessarily disable it for every parameter or on every policy, but just do so on policies/parameters that are problematic.