Forum Discussion
KellyS_50017
Nimbostratus
Nov 11, 2009http_to_https http profile rule question
Hopefully a super-easy question about the built-in http class profile rule, http_to_https. A client of ours is saying HP's WebInspect is dinging us with a security flaw when it tries to get into areas...
hoolio
Cirrostratus
Nov 11, 2009No cookie should be set in a response generated from LTM unless you explicitly configure it. Nor could the app set a cookie if the request is never load balanced by LTM. I was assuming the client was sending a cookie in the request to the HTTP VIP.
Can you use a browser plugin like HttpFox for Firefox or Fiddler for IE to check what cookies are being sent/received on a request to the HTTP VIP? Or did the pen test report contain examples of the issue? Either way, if you can post an anonymized copy of the HTTP request/response headers the client sees it would help identify the issue.
Aaron
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects