Forum Discussion
gmt20trisc00
Nimbostratus
Jun 17, 2022WAFの検知テスト(WAF detection test)
AWS WAF(F5マネージドルール)が正常に適用されているかどうかをテストする方法を教えてください。 WAFによってブロックされていることを確認したいと思います。 Please tell me how to test whether AWS WAF (F5 Managed Rules) is applied normally. I want to make sure it is bloc...
Daniel_Wolf
MVP
Jun 18, 2022Hi gmt20trisc00,
are you looking for a basic test to verify that the rules are detecting attacks? You could try some proof of concept exploit like appending one of these two examples to your URL.
/?cmd=cat%20/etc/passwd
or
/<script>alert("XSS Attack");</script>
That'll do no harm, but an active WAF should block these requests (or, if not in blocking mode, raise an alert).
KR
Daniel
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects