Forum Discussion
[ASM] - How to disable the SQL injection attack signatures
Hi Team ,
We have a request to deactivate the SQL Injection attack signature at the URL level . Below are the details .
Kindly , please help with the detailed steps to manually disable the 2 attack signatures ..
Attack Type : SQL-Injection
Requested URL : [HTTPS] /stock/option/getexcelfile
Host : trade-it.ifund.com
Attack Type : SQL-Injection
Detected Keyword : RS% -OR%16%1600021-02-2385433%16%C3%
Attack Signature : SQL-INJ expressions like ""OR 1=1"" (3) (Parameter) = 200002147
Detected in : Element value
Detected Keyword : D'OR%20SA%16%1611%2F08%2F2021%0D%
Attack Signature : SQL-INJ expressions like ""' or 1 --"" = 200002419
Detected in : Element value
Security ›› Application Security : Parameters : Parameters List
Parameter Name : ? >> what will be the parameter name ?
Parameter Level : /stock/option/getexcelfile
Parameter Value Type : user-input value
Under attack signature >> we have to add 2 signature and disable it ?
Can we deactivate both Signatures under 1 parameter rule ?
Thank you in advance !!!
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com