Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fabs
New Contributor III

Since version 7.60 flood of IPS HTTP.Suspicious.Headers.With.Special.Characters

Hello all,

 

Since yesterday I got a flood of our IPS about the following:

 

date=2024-10-10 time=09:55:22 devid="FG100XXXXXXXXXXXX" devname="100f_serverroom" eventtime=1728546922552439440 tz="+0200" logid="0419016384" type="utm" subtype="ips" eventtype="signature" level="alert" vd="root" severity="low" srcip=xxx.xx.xx.xx srccountry="Reserved" dstip=157.240.247.61 dstcountry="Netherlands" srcintf="VLAN72" srcintfrole="lan" dstintf="wan1" dstintfrole="wan" sessionid=1996577 action="dropped" proto=6 service="HTTP" policyid=6 poluuid="016585d8-cf8c-51ec-1bc2-98b96e341900" policytype="policy" attack="HTTP.Suspicious.Headers.With.Special.Characters" srcport=49694 dstport=5222 direction="outgoing" attackid=48934 profile="high_security" ref="http://www.fortinet.com/ids/VID48934" incidentserialno=168450119 msg="http_decoder: HTTP.Suspicious.Headers.With.Special.Characters" crscore=5 craction=32768 crlevel="low"

 

The destination is a meta-whatsapp service. This seems to happen with every message or interaction in WhatsApp that is made by a device.
It is interesting to note that this only started since I updated the version to 7.60 Build3401.
We have a Fortigate 100F

In order to prevent flooding, I wanted to deactivate logging specifically for the signature “HTTP.Suspicious.Headers.With.Special.Characters”, but unfortunately this does not work.

 

  edit 2
                set rule 48934
                set log disable
                set action pass
            next
        end
    next 
end 

 

Thanks in advance

1 Solution
pminarik
Staff
Staff

Just a guess: The snippet shows "edit 2", implying that it may not be the only entry in that table. If there are more entries, make sure this one is moved to the top of the list/table, as the entries are actioned in top->down order.

[ corrections always welcome ]

View solution in original post

2 REPLIES 2
pminarik
Staff
Staff

Just a guess: The snippet shows "edit 2", implying that it may not be the only entry in that table. If there are more entries, make sure this one is moved to the top of the list/table, as the entries are actioned in top->down order.

[ corrections always welcome ]
fabs
New Contributor III

Thanks, this was the issue.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors