Forum Discussion

Randy_Toombs's avatar
Randy_Toombs
Icon for Nimbostratus rankNimbostratus
Jul 01, 2019

Best way to manage Directory Traversal attempt "..\" signature that is causing issues

I am trying to help tune an ASM policy that the app has several places where the user enters in information and most are larger forms where the user has plenty of room to answer some questions. We have found that some times they will press enter to get a new line in the form and the app will add this by using ..\n to create the new line in the actual info sent back. This is getting flagged for the Directory Traversal attempt "..\" signature and before I just disable that signature I wanted to see if there were some better ways to manage it. I have already discussed this with the app developers and they said they can put in a request to update this in future revisions of the app but for now I really don't want to just turn off this signature.

Any suggestions as to ways that may be better for allowing this traffic and not turning off the signature? I already know that I can disable it by URL or parameter but even then I feel this may leave it more open that I would like.

No RepliesBe the first to reply