Forum Discussion
Dave_Pisarek
May 19, 2021Cirrus
XFF and sleep
Recently I was asked about mitigating the below XFF header: X-Forwarded-For: (select(0)from(select(sleep(5)))v)/*'+(select(0)from(select(sleep(5)))v)+'"+(select(0)from(select(sleep(5)))v)+"*/ ...
Daniel_Wolf
May 19, 2021MVP
Hi Dave,
you can block this by enforcing Attack Signature ID 200000074 (SQL-INJ "end-quote select" (Headers)).
Another approach could be to use an iRule or LTM Policy to scrub any XFF header from the HTTP Request. Unless there is a device in front of the BIG-IP that would insert such header, why would a client send a XFF header...
KR
Daniel
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects