Forum Discussion

LEON_LI_38034's avatar
LEON_LI_38034
Icon for Nimbostratus rankNimbostratus
Aug 28, 2013

About scan ASM VIP

I get through the software (Web Application Firewall detected by Acunetix) to scan my F5 ASM VIP (TMOS 11.3.1 HF6). Results show that the WAF is F5 ASM. How do I set in F5 ASM, that can prevent Acunetix scanning is not ASM F5.

 

5 Replies

  • scan overview image link https://devcentral.f5.com/Portals/0/Users/146/34/38034/acunetix%20waf%20scan.JPG

     

  • first of all what is your exact goal? do you want to be able to scan the actual webserver without WAF? or do you want to disguise that a WAF is in front of the webserver?

     

    i don't believe you can surpress the ASM cookie or rename it, so it is going to be detected.

     

  • Hello

     

    Asm can be identified by its blocking page response or specifoc asm cookies injected. But if acunetix do like qualys, there is no real ways to hide that you are using asm as they fingerprint the tcp stack used by bigip (fingerprinting, tcp response latency,...)