Forum Discussion

Kash_276820's avatar
Kash_276820
Icon for Nimbostratus rankNimbostratus
Mar 16, 2017

Evasion Techniques Blocking -Multiple decoding

Evasion Techniques Blocking -Multiple decoding

 

We are getting genuine traffic blocked by ASM with the reason of possible Evasion Technique(Multiple Decoding).

 

We changed decoding passes from default to 5. Still it blocking. Is there way to allow genuine traffic? What is the risk if we disable url normalization? or disable multidecoding viloation? what is the correct process?

 

Many Thanks!

 

2 Replies

  • Examples of your requests which get blocked? difficult to understand what is going on without an example. This rule is known to produce false positives when % character is used, for example in password fields. In such cases % character can be allowed on specific parameter (e.g. password) as an excpetion without making policy less secure. If you disable the rule hackers can easily hide their attacks by encoding the payloads