Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiWeb wgt-rpc separator based content cause command injection alert
Dear forum!
We had detect a problem with a WAF device which is protect a wgt-rpc based web application. The application receive content between "|" separator and some of the content could cause the alerts.
The sample is :
"|java.lang.Long/4227064769|1|2|3|4|5|6|1|7|7|6|8|CC$0|8|CC$d|8|CC$e|8|CC$v|8|CC$w|8|CC$x|"
The problematic contens are: A „|CC” és a „|$CC”
All the codes accour OS command injection attack alerts.
How could we safely resolve the issue? Could you examine these type of object and could you describe the pattern which type of attack could contain this type of patterns?
Best Regards
Imre Szollosi
Labels:
- Labels:
-
Web Application Firewall
0 REPLIES 0
