Forum Discussion
F5 Blocking = Illegal Method: OPTIONS
F5 is set to learn and alarm. The Attack Type is Information Leakage. The Request Details indicates Illegal method for HTTP Method OPTIONS. The HTTP Request = OPTIONS / HTTP/1.1 I am trying to determine if I should set this to BLOCK, but I do not really understand what the request is. Can you help me to understand, please?
4 Replies
- What_Lies_Bene1
Cirrostratus
See here for some details: http://www.acunetix.com/vulnerabilities/options-method-is-enabled/.
I don't think it's a real risk, any reasonably secure site/server will have unused or 'dangerous' methods disabled etc. but always better to be safe I suppose. More security theatre than anything.
- Richard__HarlanHistoric F5 Account
When a systems send a Option command it is asking the server what methods do you support/allow. The server will respond with methods like GET/POST/HEAD and such.
- MSZ
Nimbostratus
Which method we can use ACT as Method instead of OPTION method? Please
- What_Lies_Bene1
Cirrostratus
Options is a HTTP Method, used by a client to obtain from the server which other Methods are supported.
If you need a primer on HTTP I'd suggest you go to http://university.f5.com/ and take the HTTP Basics I and HTTP Basics II courses.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com