Forum Discussion
malikjengineer_
Nimbostratus
Nov 17, 2017ASM detected possible Detection Evasion and HTTP Command injection in traffic
detected possible Detection Evasion and HTTP Command injection in traffic sourcing from hosts destined for F5 VIPs via port http 80. no indication of activity being blocked/denied.
Is this a Ap...
Chris_Grant
Employee
Nov 18, 2017Those are part of your ASM security policy. Whether or not it was blocked would be based on your settings. You can read more about attack signatures and evasion settings here:
or here:
https://support.f5.com/kb/en-us/products/big-ip_asm/manuals/product/f5-asm-operations-guide.pdf
Basically ASM is reporting that someone tried to attack your web infrastructure and tried to do it in such a way that they would slip past a web application firewall. Normally this is done by encoding a string multiple times.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects