Forum Discussion
Mykola
Oct 26, 2024Altostratus
Enhancing Web Server Security via F5 Cookie Hash Exposure
I have a suggestion to improve web server security against CSRF attacks by leveraging the F5 load balancer's persistence cookie. Overview: - Current Functionality: F5 creates a persistence co...
zamroni777
Oct 26, 2024Nacreous
you can extract the client side f5 persistence cookie from http request then add it into custom http request header on server side using irules or local traffic policy.
i think the reason it is not default right now is backend web/app servers might not expect such extra request header/cookie and might treat such requests as faulty application requests.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects