Forum Discussion
Kevin_Stewart
Oct 29, 2013Employee
Is this in lieu of ASM?
when HTTP_REQUEST {
if { ( [HTTP::method] equals "GET" ) and ( [HTTP::version] equals "1.0" ) and not ( [HTTP::header exists Accept] ) and ( [HTTP::header User-Agent] contains "Mozilla" ) and ( [HTTP::header exists Referer] ) } {
log local0. "Possible Pandora/Dirt Jumper type 0 1 2 attack."
reject
}
}
The following also suggests a randomized Referer header: