Forum Discussion
Gustavo_Lazarte
Nimbostratus
Oct 09, 2009Cross-Script Audit
Hello,
I have upgraded to version 10.0 and I got audited with this cross-script vulnerability. I thought I turned off on 9.01. Do you know if I can trun off Cross-Script attacks on the F5?
Thanks
- hoolio
Cirrostratus
Was the XSS issue found in the admin web interface or in the web application you're load balancing? What were the specifics of the XSS vulnerability? - hoolio
Cirrostratus
dupe - hoolio
Cirrostratus
dupe - Gustavo_Lazarte
Nimbostratus
The xss was found on the site we were load balancing. It did not appear when we were on 9.01. We probably fixed the issue a couple of years ago. But in 10.0 it showed up again - Gustavo_Lazarte
Nimbostratus
It showes up in firefox, not in IE 8 - hoolio
Cirrostratus
I can't see how adding a standard HTTP VIP on LTM would fix a XSS vulnerability in a web app. By default, LTM doesn't change the content of HTTP requests or responses. So unless you had an iRule or ASM enabled previously (well, not ASM as it wasn't available in 9.0/9.1) I don't think load balancing an application with LTM could have fixed the problem. - Gustavo_Lazarte
Nimbostratus
We got flagged because a Firefox XSS error. - hoolio
Cirrostratus
You could try to handle this in an iRule, but there are simply too many ways that an attacker could send malicious requests to the application that it's not really feasible to try and handle them all in an iRule. I'd suggest you consider having the application fixed so that all user input is properly validated and sanitized, and implementing an application firewall.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects