Forum Discussion
IT_Support_-_EC
Nimbostratus
Jul 12, 2015[BIG-IP 4000s] Failed to protect Crosse-Site Request Forgery
Dear F5 Team,
Our team did PoC of Cross-Site Request Forgery but it seemed
that WAF cannot protect this attack. Our team said
"For the CSRF protection, F5 will generate its own Javascript t...
IT_Support_-_EC
Nimbostratus
Jul 14, 2015Mr. Boneyward,
This is the reply from our team after reading your comments
" - I had tried enable all three options (alarm, learn, block) but it's not helped - This is not the dynamic generated code case (the security.php link is static in the homepage) - I wanna see the F5 CSRF token generated with the security.php link, but that not happened. And F5 no blocked CSRF violation when I access security.php without token. "
Thank you
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects