Forum Discussion

securityninja_2's avatar
securityninja_2
Icon for Nimbostratus rankNimbostratus
Mar 20, 2017

ASM information leakage category attack type

Hi there,

 

Can anyone please explain why the following attached HTTP-request traffic categorized as "information Leakage" in ASM traffic log? Thanks

 

2 Replies

  • Based on your screenshot my wildest guess would be that your persistence cookie isn't encrypted and has the default name. (and that it is leaking the internal ip address and server port)

     

    I can tell your internal server listens on port 443 and it's ip address end's with .152

     

    The ASM could see this as information leaking.

     

    Cheers,

     

    Kees

     

  • Sai,

     

    If you enable cookie encryption on the cookie persistence profile, does this mitigate the information leaking?

     

    Cheers,

     

    Kees