Forum Discussion
Erlend_123973
Nimbostratus
Sep 16, 2014How to securely present user supplied data in HTTP::respond NNN content
When i write iRules, I often use something like
HTTP::respond 403 content "Error: variable $somevar not in datagroup"
My concern here is,
$somevar is userdefined data - often a part of HTTP::pa...
What_Lies_Bene1
Cirrostratus
Sep 16, 2014I'm no security expert but if the value is user supplied the user would be only be 'attacking' themselves as only they would get this response?
If the user was 'innocent' and had clicked a malicious link to cause this, why would the attacker use this method, the original link would have sufficed?
You can use URI::decode to expose some practises and also split the $somevar data in some way with spaces (HTTP::path 'space' HTTP::uri) so the link isn't actually 'clickable'.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
