Forum Discussion
locki
Jun 30, 2023Nimbostratus
How to secure url on irule on F5?
I need secure one think and i dont know how to do it correctly and properly. We have this link on website for aplication: https://www.somewebsite.com/test/UI/Login?realm=external&goto=https://www.so...
Daniel_Wolf
Jul 01, 2023MVP
Hi locki,
seems your app is vulnerable to open redirects. Take a look at the following links to learn more:
- OWASP Cheat Sheet Series - Unvalidated Redirects and Forwards
- MITRE - CWE-601: URL Redirection to Untrusted Site
- PortSwigger - Open redirection
Can be fixed with ASM (BIG-IP v16.1): MyF5 > BIG-IP Application Security Manager: Implementations > Mitigating Open Redirects
IMHO it should be fixed in the app code by your developers.
KR
Daniel
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects