Forum Discussion
sol14634: SSL / TLS BREACH vulnerability - CVE-2013-3587: When is this going to be fixed?
looking at it again the attack isn't that simple. do the three requirements even apply to exchange?
static content can still be compressed apparently, the iapp only compresses some of the content, is that only static perhaps?
i still don't feel F5 is the one to "fix" this. if you feel differently why not open a support ticket and explain them how to do that.
if the site of the discoverers is correct then adding random amounts of data to responses is also a workaround. that should be possible with an iRule, so in that way you even have a mitigation available with a BIG-IP.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com