Forum Discussion
Lazar_92526
Nimbostratus
May 22, 2013SQL-INJ "drop Schema" reporting in ASM 11.3
All,
In our 11.3 ASM, we triped an attack signiture detected for the following. Looking to understand why this registered? I see schema included as part of the parameter value, but is tha...
hoolio
Cirrostratus
May 24, 2013Hi Lazar,
The signature is looking for drop and schema and a fairly complex regex. It's not just looking for those two key words.
If you're seeing false positives on just one parameter, I'd disable the signature on a new global parameter with that name. If you're seeing false positives on several parameters, you could disable the signature across the policy.
Aaron
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects