Technical Forum
Ask questions. Discover Answers.
cancel
Showing results for 
Search instead for 
Did you mean: 

ASM / WAF : block request containing certain string?

AndréB
Nimbostratus
Nimbostratus

I have added as much XSS blocking to a policy as possible. A request containing onmouseover or onclick or .... ="alert('hello')" is blocked fine.

But when it's coded like onmouseover or onclick or .... ="self['\x....... the ASM accepts this as valid.

Can I block a request with this parameter value?

How do I achieve this?

 

1 REPLY 1

aglinka
Nimbostratus
Nimbostratus

Please give example of Your blocking rule You are currently implementing.