Forum Discussion
How to block phpshells?
Hello , I have a Server behind the F5. I want to mitigate the webshells [ phpshell , aspshell etc] security. ive heard that it works with the asm. how i make it work on a specific VS?
Thank you .
1 Reply
- Jad_Tabbara__J1
Cirrostratus
Hello Chenco,
You need to create an ASM policy and add it to your existing VS.
If you are not familiar with the ASM it can be a difficult task because if you put it in Blocking mode it may generate a lot of false positives.
So you need to :
- create the ASM policy in transparent mode (learning mode)
-
assign the Attack Signatures Sets that corresponds with your backend server (OS, Webserver, Language, Database). When you assign the Linux OS Signatures it will automatically add signatures that prevent "Kill, exec" and other command execution... The F5 will look at the POST method body and URL and apply the Attack Signature (make sure that on your wildcard HTTP/HTTPS URL you check the "Attack Signature")
-
prevent specific file extension upload, by making a whitelist of authorized file extension. You can do this fom "Security ›› Application Security : File Types : Allowed File Types"
Hope it helps
Regards
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com