Forum Discussion
ASM protection against SSRF
Anyone have experience in virtually patching an application vulnerable to SSRF (server-side request forgery) protected by ASM? If so, how did you configure ASM policy? Whitelist all allowed URLs?
1 Reply
- samstep
Cirrocumulus
F5 ASM can provide SSRF protection in many ways including response signatures, parameter type enforcement and whitelisting.
First of all you should find out:
- which URLs of the application are vulnerable to SSRF
- what the successful SSRF attack URL looks like and what is the 'good usage' URL
I assume you can get this from the pen-test report. Once you have this information it will become clearer what ASM policy changes you need to protect the application
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com