Forum Discussion
Mitigating Stored XSS Attacks with F5 Big-IP ASM: Insights Needed
I suggest you enable signature enforcement for server responses. In a lab environment it should be OK but in production it might impact the performance of the app
Yes, that's what I said. Signatures can be enforced also on responses.
- Nishal_RaiMar 06, 2024Cirrocumulus
Amine_KadimiDaniel_Wolf
Sorry for the late response.
Regarding signature enforcement on the responses, I selected the following signature set.The log events of the application:
On the file types specification of the response signatures:What would be the appropriate file types, since the script is stored on a message box.
Since the above mentioned signature was unable to detect the stored XSS payload in the response.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com