Forum Discussion
[BIG-IP 4000s] Failed to protect Crosse-Site Request Forgery
We are also waiting for the answer from F5 guy that we did PoC together as well but that guy is still busy and he will be able to answer us again next week T_T. Anyway, our team that did PoC sent me some screenshots of what he has done;
"The F5 configuration we have done:
Enable blocking CSRF

Enable CSRF protection on the security.php link

Ensure this CSRF configuration affected correct Virtual Server.After configuration, some stranges we have got:
The request to security.php link without token is not blocked (file3.png)

All F5 Javascripts are commented out when viewing the source-code of the page (file4.png)

The F5 CSRF token not generated to the security.php link."I think he already did try what your suggestions because after he saw your comments, he sent me the information above. By the way, we don't know if there is any special tool installed on the web server but i will check it later.
Thank you
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com