Forum Discussion
Mask Request Body ASM Reporting
Brought an 11.4 appliance up in the lab and the masking of the credit card number itself works but the rest of the data is still not masked. This data could be CVV etc etc that is not allowed to be logged by PCI compliance.
here is an example request that we would want to mask, replaces what would normally be card data or sensitive info.
POST /Micros/process_transaction.cgi HTTP/1.1:
Host: 192.168.1.1
Content-Type: x-VISA-II/x-auth
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache
User-Agent: VSCA
Content-Length: 158
Cookie: TS6c52a9=78f9df9fcdfa6b306b81503d3cd9b20ab7c9eb723cec0c1e51cb6853
X-Forwarded-For: 192.168.1.2
K0.90005008843003212500010001QF840840272150000007055812Y125754@HB^DUMMY /NAME H^ MY PLACE OF BUSINESS NC %
There are no tags to list as parameters, its just a raw string. Any idea how this could be masked in local logging?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com