Forum Discussion

Ahmed_Galal's avatar
Ahmed_Galal
Icon for Cirrostratus rankCirrostratus
Sep 13, 2021

attack Signature detected but i can not find keyword inside request

Hello everyone,

 

i found log for attack signature detection with the below image but i cannot find detected keyword within the request, how is that possible???!

 

    • Ahmed_Galal's avatar
      Ahmed_Galal
      Icon for Cirrostratus rankCirrostratus

      Good Morning Sam,

      hope that you are doing well.

       

      thank you for your assistance, i am now in middle of increase max log size and face memory issue that might happen or convince developer with this part of request 😂 😂

      • samstep's avatar
        samstep
        Icon for Cirrocumulus rankCirrocumulus

        if they payload is really big (is the developer uploading a file?) this might be a false positive. You could also intercept the request using intercepting proxy such as Fiddler, OWASP ZAP or Burp Suite.

        In your screenshot the signature 200000107 is detecting symbols &{