Forum Discussion

David_M's avatar
David_M
Icon for Cirrostratus rankCirrostratus
Aug 18, 2019

How to Fix this Path Traversal Blocked violation?

Hi,

 

This is v13.

 

To begin with there is not violation as such but it just shows up as attack type.

 

Here's the blocked request from event logs.

 

 

These are the evasion detection settings.

 

 

 

The blocked URL is added as an allowed URL in the policy with check attack signature on this url selected but I cannot find the path traversal signature there. Is it even being blocked as an attack signature?

 

4 Replies

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    David,

    You're on the right lines, path traversal is an attack signature attack type. In your first screenshot if you click on path traversal does it show you which attack signature triggered it?

    N​

    • David_M's avatar
      David_M
      Icon for Cirrostratus rankCirrostratus
      Hi Nathe It doesn’t say anything about which attack signature, nope And then I cannot even see this signature listed in the url so I cannot even disable it. And some kB articles then mention it this could be due to evasion techniques detected but will that too show up as path traversal?
  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    I wonder if it's related to this issue: K86019555 I know the versions don't match up but worth raising with F5 support perhaps?

    • David_M's avatar
      David_M
      Icon for Cirrostratus rankCirrostratus

      I think yes, this makes sense.

       

      Will update.