Forum Discussion
Mitigating Stored XSS Attacks with F5 Big-IP ASM: Insights Needed
I suggest you enable signature enforcement for server responses. In a lab environment it should be OK but in production it might impact the performance of the app
Yes, that's what I said. Signatures can be enforced also on responses.
- Nishal_RaiMar 06, 2024
Cirrocumulus
Amine_KadimiDaniel_Wolf
Sorry for the late response.
Regarding signature enforcement on the responses, I selected the following signature set.The log events of the application:
On the file types specification of the response signatures:What would be the appropriate file types, since the script is stored on a message box.
Since the above mentioned signature was unable to detect the stored XSS payload in the response.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
