Forum Discussion
Craig_C_
Nimbostratus
Sep 24, 2014Has anyone written an iRule to filter CVE-2014-6271?
CVE-2014-6271 was made public today, potentially wreaking havoc on apache/bash. Has anyone written an iRule to filter this vulnerability from HTTP GET requests?
Marc_LeBeau
Nimbostratus
Sep 25, 2014Below are two ASM signatures that have to be created separately. The concept on the pcre version is this will detect the initial brackets which are necessary and then the white space, to multiple white spaces before the curly which is also necessary. Whitespaces are usually ignored and can be repeated so but a white space can not be between the () or else it will fail so this signature detects the variances that could be used.
headercontent:"shellshock"; nocase;
pcre: "/()(\s+)?{/Hi";
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects