- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
HTTP header injection
Hello,
how we can block http header injection in fortiOS.
if the IPS what is the name of signature.
thanks
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for your answer.
no I mean http header injection attacks
not http sql injection
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This one is HTTP header injection, protected by FortiGate but it concerns Oracle WebCenter Sites.
https://www.fortiguard.com/encyclopedia/ips/35215
The above is included in IPS signatures.
Unfortunately I couldn't check if "HTTP header injection" is included in FG's WAF signatures since it seems not documented by Fortinet.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
for oracle websever it does not concern us, this attack concerns our website it is qualys which detects this attack.
for my part I am looking for a solution that will protect us from this attack “HTTP header injection" whether it is IPS or WAF signature FG.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Saad1
You can create a custom IPS signature. Please refer here: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-configure-custom-IPS-signature-for-...
APAC TAC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
what is the f-sbid for http header injection please.
