Forum Discussion

ee's avatar
ee
Icon for Nimbostratus rankNimbostratus
Oct 01, 2024

Why does WAF block HTTP OPTION method

Does the HTTP Option method pose significant security risk to the web application? 

  • Hi ee 

     

    i have read in so many articles relating the threats by option method, main thing is attackers mostly using it. if an application doesn't need the method, no need of using it. so as per awaf by default below mentioned only allow if it's a blocking profile.

     

     

     

    BR

    Aswin