Forum Discussion
Bot Protection marks Samsung Internet as malicious
Hello,
We have discovered that after Samsungs latest upgrade of the built in "Internet" (Samsung Internet Browser) 17.0.1.69, the bot protection both in transparent and blocking mode adds the cookie who is responsible for marking the device as malicious.
When logging, we can see that first visit it is just a regular device. No bot, no malicious activity and so on. Next refresh of the site will immediately make a Connection Reset. Dumping pcap shows that handshake is done and Application data begins then it stops.
With that said. If you remove this cookie, everything works fine again. It is a TS****** with a expire date seven weekdays of the first visit. Then you need to clear cache and cookies on the device to get it to happen again.
We are still looking for a solution, adding the browsers user agent will not fix the issue for us.
Hope that this will help anybody in our seat looking for a solution. I will keep you updated if we find anything that will solve the issue,
Fredrik
Why don't you add the bot as an exception "Mitigation Settings Exceptions" or Whitelist the source IP for the Bot protection:
https://support.f5.com/csp/article/K42323285
- Fredrik_Daniels
Altostratus
Hi!
We have done this both with contains SamsungBrowser/17.0 and added it as exception. We can't whitelist on IP unfortunately. I will however look into the article again if i have missed something.
Best regards,Your Bot Protection is the F5 Advanced WAF (ASM) Bot protection right? You do not use Shape security with F5 Big-IP?
Also from some bugs in the bug tracker you may try stopping the browser verification or Change browser_legit_min_score_drop sys db to be higher value.
https://cdn.f5.com/product/bugtracker/ID693782.html
https://cdn.f5.com/product/bugtracker/ID745531.html
https://cdn.f5.com/product/bugtracker/ID742852.html
As I see many issues with different browsers better open F5 case so they can add this to the Bug tracker for Samsung.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com