Forum Discussion
Nishal_Rai
Feb 26, 2024Cirrocumulus
Mitigating Stored XSS Attacks with F5 Big-IP ASM: Insights Needed
Hello Everyone, Could someone provide insights into how F5 Big-IP ASM handles stored XSS attacks? My understanding is that ASM primarily focuses on inspecting and enforcing XSS signature set...
Nishal_Rai
Cirrocumulus
Hi Daniel & Amine,
Actually, I've been testing stored XSS payloads on DVWA, bypassing F5 ASM, and requesting via F5 AWAF. Like trying to create a scenario when the client is unaware that there application has been affected by the stored xss payload.
Wondering if F5 ASM can detect and block responses containing these payloads from affected servers. Any insights?
Daniel_Wolf
Mar 01, 2024MVP
Just had the time to look into this. Only found one signature that is tagged XSS and is applied to responses.
You might miss a stored XSS.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects