Forum Discussion

Clk's avatar
Clk
Icon for Altostratus rankAltostratus
Dec 14, 2022

Wildcard Parameter signature attack

Hi,

I have a wildcard * Parameter and it's not found signature attack.

Tried to make an SQL injection with only the wildcard Parameter and the request didn't show the violation, but when adding the parmater name the attacked signature was blocked.

Is the wildcard Parameter not blocking signature attack?

  • Thank you for your answers.

    The problem was in the Parameter data type, it was in Email type ( i figured that this is the default entity when new policy is created).

    In Email type there's no signature enforce.

  • Hi Clk , 

    This is the Wildcard parameter from my Lab , an it contains all attack signatures : 

    > could you clarify more about your request 
    Regards 

    • Clk's avatar
      Clk
      Icon for Altostratus rankAltostratus

      I don't have the attack signature tab in the wildcard Parameter, even when switching the value type to auto.

      Do i need to change something in the policy setting?

      • Hi Clk , 
        > What type of your policy ( parent or security policy ) ? 
        > Could you please send a snap shot from the wild card parameter configuration ? 
        > What about Data type , Meta characters ?? 


  • Hello CLK,

    Is the wildcard Parameter not blocking signature attack >>>  No

    just make sure that the policy was in blocking mode, Wildcard Parameter was not in staging mode and finally that your attack signatures also were not in staging mode.

     

  • Clk's avatar
    Clk
    Icon for Altostratus rankAltostratus

    Thank you for your answers.

    The problem was in the Parameter data type, it was in Email type ( i figured that this is the default entity when new policy is created).

    In Email type there's no signature enforce.