Forum Discussion
khos77
Jul 20, 2022Nimbostratus
F5 rules for AWS WAF
I have enabled the OWASP top 10 ruleset on one of our AWS WAFs however we are still seeing a High vulnerability for Reflected Cross-Site Scripting (XSS) in HTTP Header. Specifically in the cookie's cc_mode parameter.
I am looking for a way to protect against this type of attack.
- Erik_NovakEmployee
Can you add the cc_parameter to the ruleset and then apply attack signatures to that parameter?
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects