Fortiweb:Parameter mensaje in log-attack-attack-view
We have a block in the Fortiweb Log see 7.25 in the attacks section, which although we put an exception in the signature with Regular Expression, it does not make it exceptional and causes us a "false positive"
The blocking occurs in a "parameter" that the Web does not have and is called "message", in which, if different "parameters" of the web are seen, it is like the "message" parameter is generated by the WAF in the Log and although in the exception of the signature, we refer to this parameter called "message", it cannot be exceptionalized, although within the "message" parameter, there are the parameters that carry the values ​​of the lock.
Parámetro: mensaje
Mached Pattern: 0000000000000077
id_original=null&ref=null&idx_cert=&numr_ref_delta2=522287&ano_ref_delta2=2023&trab_codg_ipf=1&trab_ipf=79410826Z&egc_num_expediente=00000000000000774997&trab_ccc=38000169404&trab_naf=381071694164&codg_prov_centro=38&fech_accidente=2023-06-21&fech_baja=2023-06-21&pat_num
Ejemplo Excepción de la firma: 090410001
Element Type: Parameter
Operation: Regular Expression Match
Name: mensaje
Check Value of Specified Element True
Value: 0*(\d)
Concatenate OR
