Forum Discussion
ASM Brute Force Protection feature inserts the script to response headers. How it may be removed?
Hi SerhiiR,
this looks like Device ID is enabled in your bot defense profile. Can you verify?
For Login Page protection you can use Device ID, I'd even recommend to use it. But in case it causes an issue with your application, you may either debug why your app has a problem with sideband loading of JS or just switch the Device ID feature off.
KR
Daniel
Hello Daniel,
Thank you for the recommendation. But we do not have the bot defense profile at all. From the Brute Force Protection configuration, the device ID is switched to Never Trigger.
- Daniel_WolfMar 20, 2023MVP
Other features that might cause JavaScript injection.
- Analytics profiles
- CSRF protection
- DoS protection profile using Client Side Integrity Defense.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com