Nishal_Rai
Feb 26, 2024Cirrocumulus
Mitigating Stored XSS Attacks with F5 Big-IP ASM: Insights Needed
Hello Everyone,
Could someone provide insights into how F5 Big-IP ASM handles stored XSS attacks?
My understanding is that ASM primarily focuses on inspecting and enforcing XSS signature sets on incoming requests. However, stored XSS attacks involve legitimate requests but malicious scripts embedded in server responses.
While attempting to enforce ASM's XSS signature set on server responses seems impractical, I'm curious if ASM has the capability to analyze and mitigate XSS vulnerabilities within server responses.
Can anyone shed light on this aspect of F5 ASM's functionality?"