For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

misch43's avatar
misch43
Icon for Nimbostratus rankNimbostratus
Jan 17, 2023

ASM: Apostroph (0x27) char in header value

Hi,

we see HTTP requests comming in where the User-Agent header ist delimited by an apostroph (0x27 ASCII). The ASM flags this as a violation and suggests me to allow that char.

As far as I unterstand RFC7230 sec 3.2.6 this char is NOT allowed as delimiter, but as contents (tchar).

Am I correct? Should I ignore the ASM suggestion?

Michael

2 Replies

  • It depends on:

    • if you want to allow the client, you must disable this protection
    • else ignore the suggestion

    There are some browsers, mostly from smartphones, that violates the rfc's and sends non-ascii characters in headers.

  • Hi misch43 , 
    I recommend to ask server developer. 
    Take some samples from F5 Violated requests " Contains Apostroph " to Backend server developer to review it with him to take the proper action against this violation , if you should allow or Block it.