QuestionQ2

Implementing Protections

Scenario: While troubleshooting an application, the web application developer observes that response traffic received from a protected web application does not match the traffic being sent by the web server. A Citrix Engineer is concerned that someone is trying to gain unauthorized access to the application.

Which NetScaler Web App Firewall action would cause this false positive?

Explanation

NetScaler Web App Firewall Form Field Consistency protection inserts the hidden as_fid field into response forms to detect unauthorized changes to form structure or hidden-field values. The client-visible response can therefore differ from the server-originated response, and application-side form checks that do not account for the added field can cause false positives.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!