For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

3 Replies

  • Can you explain little more about this question? Whats the issue with parameter name? Is it allowing explicitly or blocking it?

    You can review the parameter set for your specified policy from here.

    Security  ››  Application Security : Parameters : Character Sets : Parameter Value

    But please make sure you are not allowing or disabling the wrong one.

    -Jinshu

  • Are you sure that the language encoding for the policy matches the application?

     

  • Encoding validation can be done using this link: http://validator.w3.org/

     

    However, if you are getting some correct parameter names, then most likely the language encoding is correctly configured. The names in the screenshot are a bit hard to see. Is the app using Base64 encoding or are any metacharacters (!@%^) associated with the parameter? Are there any other violations associated with the illegal parameter name?