For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Maz_Oni_59368's avatar
Maz_Oni_59368
Icon for Nimbostratus rankNimbostratus
Jul 04, 2014

ASM XSS Protection

Hello All,

 

When configuring ASM, I need to enable Response Signature to block simple XSS such as window.alert.

 

Please inform which kind of XSS that can be blocked WITHOUT enabling Response Signature.

 

Thank you,

 

1 Reply

  • I don't believe there are any XSS signatures which apply to responses; they apply only to requests. As for the kind of XSS that can be blocked all we have to go on is the name of the signature since the actual expression cannot be seen.