Forum Discussion
Rodolphe_AUBINE
Nimbostratus
Jun 28, 2010Cookie not RFC-compliant with Asp.net flows
Hi,
I have some strange blocked requests because of "Cookie not RFC-compliant".
Examples :
Invalid carriage return, Invalid equal sign preceding cookie name, Invalid space i...
hoolio
Cirrostratus
Jun 28, 2010Hi Rodolphe,
There is a bug with cookie parsing in ASM in several versions:
SOL10764: Large POST requests may trigger BIG-IP ASM cookie violations
https://support.f5.com/kb/en-us/solutions/public/10000/700/sol10764.html
However, it looks like snippet you've posted is being parsed incorrectly by ASM. This "prod/callpayment0xd0xaCookie:0x20JSESSI" looks like a prior header value, a carriage return and line feed and then the start of the cookie header.
Can you post an anoymized copy of the full request?
Thanks, Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
