Forum Discussion
jksingh_44237
Nimbostratus
Jan 04, 2010The remote load balancer suffers from an information disclosure vulnerability at port 80 and 443
I am looking a solution for this issue.....
I have BIGIP (BIG-IP 9.3.1 Build 37.1)
Port http (tcp/80)
Synopsis :
The remote load balancer suffers from an i...
hoolio
Cirrostratus
Mar 23, 2011I submitted an internal request to add a checkbox option to the cookie insert persistence profile for encryption and an encryption passphrase to make it very clear that you can encrypt the cookie value and simple to do so.
Hamish, I can see both sides of your request. From a security standpoint, I think it's a good practice to limit the amount of information you give potential attackers. But I think the actual security risk is fairly low and the performance hit for the encryption is not nothing.
Anyhow, if you'd like to see such a feature added in a future version, you can open a case with F5 Support and request this change. If you get a RFE ID, please reply back here with it for others to reference.
Thanks, Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
