Forum Discussion
Henk_Oostland
Nimbostratus
Jun 12, 2017SQL injection problem!
We have an application VIP with an ASM profile. The application runs on Windows, IIS, ASP.net and SQL server.
Our BIGIP runs TMOS11.5.4HF4.
The application requires a login. When we fill in: 1'or'1'= '1'in te username field, ASM blocks the request. When we fill in: 1'or'1'= '1'-- ASM does not block the request.
What is the problem?
3 Replies
- nathe
Cirrocumulus
Henk, do you have the following Attack Sigs associated to your ASM Security policy and not in Staging? 200002430, 200002419, 200002444?
- Henk_Oostland
Nimbostratus
Yes, that was the problem, the attack sigs were in staging.
Thanks!
- nathe
Cirrocumulus
Glad u sorted
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects