Forum Discussion
Nik_67256
Nimbostratus
Mar 05, 2012CSRF Protection Query
Hello,
Have a query on CSRF protection. In ASM in Policies -->CSRF Protection screen , the user needs to specify the specific URLs of the webapp to protect. I ran a appscan scan on my webapp(for URL discovery) and it threw about 700+ application URLs.
Query:
Does this mean i need to specify all these specific application URLs to completely protect my site or is three any other way to do this.
regards,
Nik
2 Replies
- hoolio
Cirrostratus
Hi Nik,
Can you use wildcards for this? At least in 11.1 ASM supports wildcards for the CSRF URL list.
Aaron - Nik_67256
Nimbostratus
Hello Aaron,
I have asm 10.2.2 running. I did try the wildcard expression, but dont think it works
I added https://siteURL/* in the CSRF protection page. I then did a explore with a scanner which conducted the CSRF
tests. However the asm traffic learning screen did not flag it as an event.
Queries
1) Firstly, Will this approach (described above) work in asm version 11
2) How can CSRF protection be achieved in asm version 10.2.2
regards
Nik
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects