Technical Forum
Ask questions. Discover Answers.
cancel
Showing results for 
Search instead for 
Did you mean: 

blocking ZAP tool

kaoutar
Cirrus
Cirrus

Hi All,

we noticed recently that some attackers use the ZAP tool to scan our web apps and most of those requests generate some issues, we tried to block these requests using attack signature based on string contains ZAP but it didn't match, so could you please suggest me another way to block these requests.

thank you

5 REPLIES 5

Paulius
MVP
MVP

@kaoutar If you can figure out an HTTP header that is always added for this tool you can block it by searching the HTTP header value and if located the connection is dropped.

Thank you @Paulius, Unfortunately the matching key exists only on the payload of the Post request, nothing unusual in the URI or the header

Is the key static? Intercepting payload content is possible with irules 

Yes, it's a static key

@kaoutar You might be able to use the following link to gather this information and then block it.

https://my.f5.com/manage/s/article/K07535385