Forum Discussion
Chris_Hotchkiss
Nimbostratus
Feb 29, 2012iRule to mitigate CSRF
Some of our application developers are asking about an iRule that could possibly insert a nonce onto a page during a session that would help prevent a cross-site request forgery from happening. Unfortunately the native software doesn't do this and has said it will be a couple of months before they can get it fixed.
I've written a few iRules but was hoping to knock this out quickly if someone could point me in the right direction. Thanks.
1 Reply
- hoolio
Cirrostratus
Hi Chris,
There is built in functionality to do this in the Application Security Manager (ASM). I guess it's technically possible to do in an iRule--but it would be complicated to try to parse each parameter from the response HTML and inject the nonce.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects