Forum Discussion
coda6_52611
Nimbostratus
Feb 23, 2009ASM and XSS
We had our website security audited recently with it sitting behind our 6400 with an ASM. The ASM was configured and had been learning for a few months and we turned to finally start blocking attacks ...
hoolio
Cirrostratus
Feb 23, 2009Hi Ken,
I'd send Ziv an email. I'm sure he'd be happy to help you get started in diagnosing/fixing the issue.
Most of the XSS-related signatures are in the "All Systems" set. Do you have this set enabled? Are the signatures out of staging? Is the policy in blocking mode for 'Attack Signature detected'?
Where in the request is the XSS? Is it in a parameter value, parameter name, header value, object, etc? Do you hvae a wildcard object and/or parameter defined? What is the text of the attack? Can you post the HTTP headers/body of the attack example?
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects