Forum Discussion
Blocking client that uses existing cookie
What makes you believe they're using an existing cookie rather than receiving a new one?
Hi,
We are running this to a UAT, and they are trying to access first the legitimate user once successfully login they copied the cookies of the legit user then it will be imported to another user browser.
- zamroni777Oct 14, 2024Nacreous
in my opinion, it's not valid test case for waf or reverse proxy such as f5 asm/ltm
because browsers also reuse non expired cookies in legitimate access.i suggest the application should add captcha to verify human users.
if you have enough apm user session license, you can also put the app access via apm webtop portal.
my customer use this mechanism for corporate internet banking access. - PauliusOct 17, 2024MVP
To be clear, this is what you did already?
https://techdocs.f5.com/en-us/bigip-14-1-0/big-ip-asm-implementations-14-1-0/preventing-session-hijacking-and-tracking-user-sessions.html
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com