Forum Discussion
Investigation/identification of WAF violations from archived F5 ASM security logs
Hi,
Please let me know how you figured it out, can you help me with the steps to figure out the same.
I tried to find some way that the 39 made sense. I found K6998 and I exported one of my Security Polices to XML. There you will find something like:
<metachar character="0x22">disallow</metachar>
<metachar character="0x23">allow</metachar>
<metachar character="0x24">allow</metachar>
<metachar character="0x25">disallow</metachar>
<metachar character="0x26">allow</metachar>
<metachar character="0x27">allow</metachar>On position 39 you will find 0x27. Now I knew the HEX and DEC representation of the character.
With this information I found the binary value and I could reverse it from the table in the RFC.
I tried a couple of other values to verify that my assumption is correct.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com