For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

danieldoe's avatar
danieldoe
Icon for Nimbostratus rankNimbostratus
May 28, 2019

Bare Byte decoding false positive

Hello, I'm tuning an ASM policy and I'm getting requests that are hitting this learning suggestion:

 

 

Action: Set Learn to disabled. Set Enabled to off.

 

Matched Evasion Technique: Bare byte decoding

 

 

I know requests are false positives (I can see from my log manager that are always the same ten requests to hit this alert), I want to create an exception in order not to block them, but I don't want to globally disable the "Bare Byte decoding" detection as suggested in "Action".

 

What options do I have?

 

 

Thank you!

 

1 Reply

  • Just suggestions, I am sure you are aware. If it is known source(IP/ URI) then can be bypass also.