Forum Discussion
haritan_132923
Nimbostratus
Sep 04, 2013BIG-IP false SQL injection alarm when trying to update a Wordpress page
Hi all, first of all, I am not sure if I ask this question in the right forum. Please direct me to the right one if this is not the place to ask this question.
I host my Wordpress-based website ...
boneyard
MVP
Sep 05, 2013200002149; SQL-INJ expressions like "and 1=1" (5). so it somewhere finds a string that looks like and 1=1 which is a common trick in SQL injection attacks.
the ASM is in front of your webserver, so it gets the data send to the webserver. so that is before PHP does something with it, but php probably did create the page where you entered the data.
as this signature is parameter based you could also just exclude it for the content parameter and have it active on all other parameters.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects