Sep 26, 2014
@Shibu - you bring up good points.  At the time I wrote the article, we couldn't determine that the exploit was limited to a "() {..." pattern so I took the route of making the search broader to make sure all bases were covered.  Since then, it has been suggested that some User-Agent strings may lead to false positives.  We are investigating this now.  As for ASM, if you are using that product, then a custom signature is a great idea.  This solution was geared for customers who are not using ASM and have iRules fronting their servers.