Forum Discussion
Mike_Maher
Nimbostratus
Oct 07, 2009Multiple Decodings
I have an application that is showing a lot of violations for Multiple Decoding. From I am seeing it looks like I can increase the value to 2 to 3, and that should help my problem but not necessarily increase my risk. My understanding is that ASM will still decode the content as many times as necessary to get to the ASCII value and protection will still be provided at that level. I wanted to get some other opinions though how does everyone else manage this setting, do you turn it on at all?
- hoolio
Cirrostratus
Is the value triggering the violation encoded more than two times? I've seen one or two bugs with this functionality in 9.4.x. - Javier_Checa_41
Nimbostratus
I always try to keep it in two decodings, but sometimes I've had to set it to 3 (when not in the mood to teach lazy programmers how they have to do their job). - hoolio
Cirrostratus
There are valid cases where the parameter values might be URL encoded more than two times. One example is XML element values in parameter values.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects