Forum Discussion
Disable buffer overflow in json parameters
Hi
In a file upload using api we allow the file name in base64 encoding.
However this triggers the
Generic buffer overflow attempt 1
.
As of this post it seems signature at json parameter level cannot be disabled. https://devcentral.f5.com/questions/disable-attack-signature-on-particular-json-parametercomment77010
Has there been any change in this? I am using v12?
In my json content profile I do not see the buffer overflow sig at all on filtering with the name.
- Lior_Rotkovtic1Historic F5 Account
try serach sig ID 200011000 in the "filter signatues by name or ID"
I tried, the thing is this box with the problem has not updated the ASM signatures.
My lab device with v12 and updated ASM sig does not even have that
buffer overflow sig anymore, but onlyattempt 1
and so on.attempt 27 28
- Lior_Rotkovtic1Historic F5 Account
not even here ? : Security ›› Options : Application Security : Attack Signatures : Attack Signature List
also, try accepitng the request from the request log - where it got block. this should disable the signautre so that it will not block
This sig is fired for this one uri in one parameter in json request, the problem with disabling it is it will disable the sig everywhere globally right?
And yes
is not even in the big sig list.Generic buffer overflow attempt 1
try serach sig ID 200011000 in the "filter signatues by name or ID"
I tried, the thing is this box with the problem has not updated the ASM signatures.
My lab device with v12 and updated ASM sig does not even have that
buffer overflow sig anymore, but onlyattempt 1
and so on.attempt 27 28
not even here ? : Security ›› Options : Application Security : Attack Signatures : Attack Signature List
also, try accepitng the request from the request log - where it got block. this should disable the signautre so that it will not block
This sig is fired for this one uri in one parameter in json request, the problem with disabling it is it will disable the sig everywhere globally right?
And yes
is not even in the big sig list.Generic buffer overflow attempt 1
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com