Forum Discussion

Muhannad_64809's avatar
Muhannad_64809
Icon for Nimbostratus rankNimbostratus
Dec 31, 2015

Protection against XSS cross-scripting infinte attacks tries.

Dears,

 

The F5 ASM is doing its job by blocking the XSS cross-scripting attacks and block the attack, this is done by the built-in signatures of the WAF. but i still able to keep trying my scripting attacks, so in theory a real attacker will be able to keep trying to attack the WebSite.

 

I want to know if i have anyway to track the number of the XSS scripting attacks and block the IP address after number of tries, i am not sure if this done by any mechanism of DOS protection or brute-force protection or maybe i can create a customized signature to track number of attacks?

 

Please let me know the best approach to prevent such attack pattern after number of XSS tries.

 

Looking forward to hearing from you.

 

Regards, Muhannad

 

3 Replies