Forum Discussion

jayson27's avatar
jayson27
Icon for Cirrus rankCirrus
Oct 11, 2024

Blocking client that uses existing cookie

Hi,

We are trying to block a client that uses existing cookie. We try to configure session hijacking protection but they are still able to connect.

May I know another method to block the client that uses existing cookie?

 

 

  • What makes you believe they're using an existing cookie rather than receiving a new one?

    • jayson27's avatar
      jayson27
      Icon for Cirrus rankCirrus

      Hi,

      We are running this to a UAT, and they are trying to access first the legitimate user once successfully login they copied the cookies of the legit user then it will be imported to another user browser. 

      • Paulius's avatar
        Paulius
        Icon for MVP rankMVP

        To be clear, this is what you did already?

        https://techdocs.f5.com/en-us/bigip-14-1-0/big-ip-asm-implementations-14-1-0/preventing-session-hijacking-and-tracking-user-sessions.html