Mar 01, 2021

Regular expession failing when adding a custom attack signature



I am trying to add a custom attack signature for a header, aiming to prevent the injection of certain

headers. My approach is to use regular experssoins as the criteria instead of "contain string".


The problem is that this does not work. For example the regular expression ^badheader stating

the string must start with the header value, this expression does not seem to work. My question, is there

a certain syntax I need to use for this scenario.


Thank you


