Since version 7.60 flood of IPS HTTP.Suspicious.Headers.With.Special.Characters
Hello all,
Since yesterday I got a flood of our IPS about the following:
date=2024-10-10 time=09:55:22 devid="FG100XXXXXXXXXXXX" devname="100f_serverroom" eventtime=1728546922552439440 tz="+0200" logid="0419016384" type="utm" subtype="ips" eventtype="signature" level="alert" vd="root" severity="low" srcip=xxx.xx.xx.xx srccountry="Reserved" dstip=157.240.247.61 dstcountry="Netherlands" srcintf="VLAN72" srcintfrole="lan" dstintf="wan1" dstintfrole="wan" sessionid=1996577 action="dropped" proto=6 service="HTTP" policyid=6 poluuid="016585d8-cf8c-51ec-1bc2-98b96e341900" policytype="policy" attack="HTTP.Suspicious.Headers.With.Special.Characters" srcport=49694 dstport=5222 direction="outgoing" attackid=48934 profile="high_security" ref="http://www.fortinet.com/ids/VID48934" incidentserialno=168450119 msg="http_decoder: HTTP.Suspicious.Headers.With.Special.Characters" crscore=5 craction=32768 crlevel="low"
The destination is a meta-whatsapp service. This seems to happen with every message or interaction in WhatsApp that is made by a device.
It is interesting to note that this only started since I updated the version to 7.60 Build3401.
We have a Fortigate 100F
In order to prevent flooding, I wanted to deactivate logging specifically for the signature “HTTP.Suspicious.Headers.With.Special.Characters”, but unfortunately this does not work.
edit 2 set rule 48934 set log disable set action pass next end next end
Thanks in advance
