Forum Discussion
Bare Byte decoding false positive
Hello, I'm tuning an ASM policy and I'm getting requests that are hitting this learning suggestion:
Action: Set Learn to disabled. Set Enabled to off.
Matched Evasion Technique: Bare byte decoding
I know requests are false positives (I can see from my log manager that are always the same ten requests to hit this alert), I want to create an exception in order not to block them, but I don't want to globally disable the "Bare Byte decoding" detection as suggested in "Action".
What options do I have?
Thank you!
1 Reply
Just suggestions, I am sure you are aware. If it is known source(IP/ URI) then can be bypass also.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com