Forum Discussion
How do I mark a non-standard parameter/field in ASM as sensitive or obfuscate it?
This data format isn't XML but rather OFX (Open Financial Exchange), a financial data exchange standard originally based on SGML.
OFX client systems are not typically web browsers, hence features like javascript aren't available. This would preclude the use of many ASM features.
Further, ASM brute force protection is restricted to specific content types (text/html, text/xml, application/sgml, application/xml, application/html, application/xhtml, application/x-asp, or application/x-aspx) but OFX data has a content type of "application/x-ofx" and therefor wouldn't be included.
Protection for OFX services is probably better provided by a combination of IP Intelligence (to exclude known bad-actor sources) and custom iRules to examine OFX requests for specific strings used for brute-force OFX attacks or to collect data to identify bad-actors for blocking.
You should probably make contact with your F5 Account team to see about resources that can help you develop a suitable solution.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
