For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

MiLK_MaN's avatar
MiLK_MaN
Icon for Nimbostratus rankNimbostratus
Sep 09, 2014

ASM with Invalid File Types and poor web coding

Hi all,

 

We are controlling allowed file types with an ASM policy, but found some poor web coding is leading the ASM to identify a particular URL as having a weird file type.

 

The end of a particular URL has "NFL0x20Season0x20No.of0x20Wins", and ASM picks this file type up as " of0x20Wins". There's no real chance of us getting the app developer to modify this behaviour, and I'm struggling to think of a way to configure the policy around it other than turning off that blocking option in ASM.

 

Anyone with some smart ideas to get around it?

 

3 Replies