Skip to main content
ddsouza_FTNT
Staff
Staff
December 6, 2021

Technical Tip: How to add an exception in a signature

  • December 6, 2021
  • 0 replies
  • 5189 views

 

Description

This article describes how to add an exception for a Signature.

Scope

FortiWeb.

Solution

Explanation:

There are multiple ways to add an exception in the Signature.


Observe the following sample attack log example (image below) generated on FortiWeb, and then see how it is possible to add an exception for the triggered HTTP request in the signature:

 

3fc87f19e94945aea5c37fc204153786.png

 

The attack log states that FortiWeb blocked the HTTP request containing the matching pattern .jsp%00 in the URI.

 

Now check what this signature is all about by simply selecting the ‘Message: RAWURI triggered signature ID 050160001 of signature policy Signature_Policy’ and then selecting the ‘View Signature’ option.

 

Pic2.png

 

The description of the signature says: 'This signature prevents information disclosure. This injection can be achieved in HTTP URL.' 

 

To explain it in detail, an attacker can make the remote web server disclose the source code of its JSP pages by appending a NULL character to the name of the JSP files requested (for example, 'foo.jsp%00', ‘test.jsp%00’).
With this signature enabled, an HTTP request containing a URI with a NULL character %00 appended to the name of the JSP files requested triggers the signature, and based on the action set, FortiWeb will perform an action.

pic3.png

 

If this type of request is legitimate in the environment, then it is possible to add an exception by using one of the methods mentioned below.

 

Method 1:
Select the ‘Message: RAWURI triggered signature ID 050160001 of signature policy Signature_Policy’ and then click on the 'Add Exception' button.

 

Pic4.png

 

It is possible to select the desired Element type based on the strictness level of the exception to add.

 

Pic5.png

 

Method 2:
Make a note of the SubType (Generic Attacks), Signature Subclass type (SRC Disclosure), and Signature ID (050160001) seen in the attack log. 

 

Pic6.png

 

Navigate to Web Protection -> Known attacks -> Signatures -> Generic Attacks(SubType) -> SRC Disclosure (Signature Subclass type) and find the Signature ID 050160001 in the list.

Pic7.png

 

Select the Exception button and add an exception.

 

Pic8.png

 

Pic9.png

 

Method 3:
The third way to add an exception is by using the search option. Add the Signature ID seen in the attack logs in the search text box and select the 'Search' button.

 

In this case, the triggered Signature ID is 050160001.

Pic10.png

 

Once the exception is added, the HTTP request matching the exception rule will not be blocked.

Related document:
Configuring action overrides or exceptions to data leak & attack detection signatures

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!