Forum Discussion
Evasion Techniques Blocking -Multiple decoding
Evasion Techniques Blocking -Multiple decoding
We are getting genuine traffic blocked by ASM with the reason of possible Evasion Technique(Multiple Decoding).
We changed decoding passes from default to 5. Still it blocking. Is there way to allow genuine traffic? What is the risk if we disable url normalization? or disable multidecoding viloation? what is the correct process?
Many Thanks!
- Kash_276820Nimbostratus
Any answers please?
- samstepCirrocumulus
Examples of your requests which get blocked? difficult to understand what is going on without an example. This rule is known to produce false positives when % character is used, for example in password fields. In such cases % character can be allowed on specific parameter (e.g. password) as an excpetion without making policy less secure. If you disable the rule hackers can easily hide their attacks by encoding the payloads
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com