Forum Discussion
Bad User-Agent Header to be blocked via ASM
You can create attack signature for User-Agent header if you know the pattern
I need to block requests containing user agent Test Certificate Info
While creating custom attack signature which option will work better from the attached snapshot.
- Ivan_ChernenkiiJul 07, 2020
Employee
I think it would be better to create appropriate Bot Signature (related to Bot Profile) and not Attack Signature (related to ASM policy), because in Bot Signature we have rule like "User Agent Contains ..."
In case of Attack Signature - IMO, "Header" matched element is preferred, but also you can make it more detailed by using regex or string with "Request Content" matched element, like "User-Agent: *Test Certificate Info*" or "User-Agent: Test Certificate Info"
Thanks, Ivan
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com