Forum Discussion
Don_Couture_211
Nimbostratus
Jul 19, 2006XSS protection with an Irule?
I have searched and browsed the forums and codeshare but have not found any examples of using an Irule to protect against cross site scripting.
Wouldn't an Irule that replaces html tags < />...
hoolio
Cirrostratus
Sep 21, 2011Hi Bill,
I don't think it's practical to implement full XSS detection in an iRule. You could try, but I think you'd always be a few steps behind attackers. iRules don't current provide native methods for handling all of the encoding methods that an attacker could use. Not to give you a sales pitch, but F5 offers the ASM web app firewall. It does provide very complete XSS protection along with a lot of other positive and negative validations for SQL injection, bots, etc. And there are plenty of competitors you could check out as well.
Aaron
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects