Jirka_Placatka_
May 12, 2017Nimbostratus
Disable ASM signature for all cookie parameters
Hello
How can I disable a signature for all cookies only? Example - I have a cookie:
Cookie: .AspNet.ApplicationCookie1 = XGtw4WmA3N_wmXLWU22Y8m1K; .AspNet.ApplicationCookie2 = XXIPqExECpMDvp4KrXsTXMS_9asdf; .... other cookies
Names of cookies are changed, the string is a random text from ASP NET. It is false positive.
SQL-INJ Stored procedure "exec MS_" (Parameter) 200002275 Context: Cookie Detected Keywords: MS_, ExEC
My settings
If the exact parameter name is specified in the cookie and the signature is blocked then the query is enabled. This is OK.
But if I use * for any name then the query is Blocked.
How can I disable only listed signatures for all cookie parameters? Can I use * wildcard character?
Thank you for your help.