Forum Discussion
George_33482
Nimbostratus
Apr 15, 2013Meta Characters
Hi ,
I have ASM 11.2.1 that starts blocking web pages due to meta character violation in the password parameters (during authentication), I allowed some meta characters for the users to be able to login.
But the question is, what is the implications of allowing special characters that are disallowed by default??? Does this causes some security violations??
Is there another way to make the ASM learn these meta characters instead of staticaly allow them?
Thank you.
George
3 Replies
- Torti
Cirrus
Hi, - Mike_Maher
Nimbostratus
So the first question you need to ask yourself is how important/sensitive is the data that lives behind this application, if it is sensitive personal data of customers or employees then I would not recommend just allowing all meta characters for all parameters, even if it is just moderately valuable data I still may not do this. If it is public data though that you don't care who has it, then restricting meta character and white list security is probably not heavily needed - Torti
Cirrus
Mike you are right. The ASM is only for an increase of security. Security starts with secure coding. If you want 100% security, disconnect from the www.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects