Forum Discussion
ASM detecting violations "top" "time" within HTTP cookies
Hello Dev Central community,
I have a question about ASM triggering violations for known attack signatures for execution attempts based on keywords "top", "time", "source", etc. and how to properly handle these false positives.
These keywords appear within the HTTP cookie, where some URI paths include "top" and other unix/linux commands.
Aside from disabling this ASM violation from the security policy - is there a way to have the F5 ASM ignore these parameters?
- Lidev
Nacreous
Hello,
You can overide specific attack signature in Security ›› Application Security : Headers : Cookies List ›› Edit Cookie.
- Its_not_the_F5
Nimbostratus
Thanks Lidev! Appreciate the response. I'll edit the cookie list.
- Lidev
Nacreous
Your welcome, if my answer was helpful, please don't forget to mark the answer as "Select as Best" in order to pass you post as resolved and help others peoples to find it.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com