Forum Discussion
Chris_Paulraj_1
Nimbostratus
Jan 20, 2009Could someone shed light on "Modified Domain Cookie" violations?
I need some help in understanding the modified cookie domain violation. Does ASM report it when a cookie gets modified at the client side (browser)? and does it also report when a cookie gets updated in another appserver (different from the one issued cookie)sharing the same domain?
-thanks
Chris Paulraj
- hoolio
Cirrostratus
- Chris_Paulraj_1
Nimbostratus
Thanks a lot Aaron, I am using V9.4.5, most of the errors I am getting are "New Cookie" with referrer obj "Entry Point". Could they be coming from book marked requests? But looking at the amount of these errors, it looks like it is more than bookmarks!! - hoolio
Cirrostratus
Is the cookie that's generating the violation set by the app with an expiration time? If so, it's possible that clients get the cookie from the app (along with a corresponding session cookie from ASM), close their browser, lose the ASM cookie, reopen the browser and then make a new request to the VIP with just the app cookie. - Javier_Checa_41
Nimbostratus
Hello cpaulrag, - Chris_Paulraj_1
Nimbostratus
Thank you Javier, You are right on, we do see those violations. Does it also flag when the protocol is switched? We get Bigip affinity cookie from our public site using HTTP and when we switch to HTTPS at the time of login, it is flagging both affinity cookies with Modified Domain cookies violation. (two different pools - one for HTTP and one for HTTPS) - Chris_Paulraj_1
Nimbostratus
Aaron, I am able to reproduce the problem, all our application cookies are created with Session expiry and so are the F5 cookies (affinity & ASM). I also see a problem with the way ASM is reporting on these cookies, cookie name & value are misplaced on the alerts, it is reporting cookie values as cookie name for some of our cookies (not all of them). However they all show up right on cookiespy & IEWatch.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects