Forum Discussion
F5Hopper_28651
Aug 27, 2012Nimbostratus
Blocking embedded JAVA and HTML
Hey Guys,
Im not sure I need to do this on a firewall level or I can do it on the F5. I have looked around and didnt find anything that matched up with what I wanted to do.
Im trying to block all request with embedded JavaScript and embedded HTTP except for the /LocationsAdmin.aspx for HTTP.
Thanks for any help
Ryan
- hooleylistCirrostratusHi Ryan,
- F5Hopper_28651NimbostratusI think for a first volly I want to attack the blocking of the embedded JavaScript. We have had some XSS attacks and their dropping in JavaScript. I thought I might be able to look for anything javascript and block it 100%.
- hooleylistCirrostratusYou could try to use an iRule validate the HTTP requests which trigger the XSS being sent to the client, but iRules aren't very well suited for doing validation of payload parameters. That's where ASM (Application Security Manager) would really help. ASM provides full validation of the HTTP/S request components and provides very good default attack signatures and meta-character enforcement to mitigate XSS vulnerabilities.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects