Forum Discussion

redheadontherun's avatar
Icon for Nimbostratus rankNimbostratus
Mar 25, 2016

Alert or Block GET requests with data

We have a webpage with a username field, we'd like to prevent malicious actions by ensuring a GET with data cannot be accomplished. I would be happy with an iRule that looked to see if there was data...
  • Tzoori_Tamam_95's avatar
    Mar 28, 2016

    I may have misunderstood the question, but if you enable an ASM policy, it is one of the basic check it enforces, under HTTP Protocol Compliance ("Body in GET of HEAD requests") - you need to make sure it is checked in the Policy Blocking Settings configuration page, and that your policy is set to Blocking.