Mitigating “Sentry MBA” - Credentials Stuffing Threat
“Credentials stuffing” attack technique became a very popular way nowadays to brute force user accounts over web applications’ login pages. Instead of trying to guess a certain user password from a g...
Published Jan 17, 2017
Version 1.0Maxim_Zavodchik
Historic F5 Account
Joined May 04, 2019
Maxim_Zavodchik
Historic F5 Account
Joined May 04, 2019
samstep
Oct 16, 2017Cirrocumulus
Where this fails miserably is on mobile apps and AJAX/JSON API requests as these do not support JavaScript and as a result ASM simply blindly blocks all traffic. CAPTCHA is also not working here as CAPTCHA image response do not work with JSON/API responses. Further work is needed by the ASM Product Development team to introduce more programmability of ASM features such as Brute Force protection and CAPTCHA in iRules