Forum Discussion

mamat_132868's avatar
mamat_132868
Icon for Nimbostratus rankNimbostratus
Oct 10, 2013

how to block hidden field manipulation

when I try to view from traffic learning, I m still able to change the value of a variable using fiddler. this is for ASM deployment. please advise

 

4 Replies

  • I'm not sure I understand your question. Are you asking about how to prevent insertion of certain HTTP headers?

     

  • i already configure all the signature attack. but unforunately i still able to change the information of the items. Eg: A bag cost 50usd. i used fiddler to change the amount to 10usd. it still can bypass the ASM firewall

     

    • Cory_50405's avatar
      Cory_50405
      Icon for Noctilucent rankNoctilucent
      Is your policy in blocking mode? How did you build your policy?
  • yeah already. I build policy using Rapid Development Policy. what the difference between normal policy and rapid development?