Forum Discussion

IT_Support_-_EC's avatar
IT_Support_-_EC
Icon for Nimbostratus rankNimbostratus
Jul 13, 2015

[BIG-IP 4000s] Failed to protect Crosse-Site Request Forgery

Dear F5 Team,

 

Our team did PoC of Cross-Site Request Forgery but it seemed that WAF cannot protect this attack. Our team said

 

"For the CSRF protection, F5 will generate its own Javascript to browser. The problem is when I viewsource the webpage, all F5 JS are commented out, so it cannot work"

 

Could you help us check how to make WAF against CSRF work?

 

Thank you

 

15 Replies