QuestionQ37

Advanced Security Features

Scenario: During a security audit, a Citrix Engineer is told that response traffic received from a protected web application does not match what the web server sends. The auditor is concerned that a Man-In-The-Middle attack is underway.

Which action is the NetScaler Web App Firewall carrying out that could cause this false positive?

Explanation

NetScaler Web App Firewall inserts the hidden as_fid form field into response pages to support form-field consistency and CSRF protection. That intentional alteration changes the response body after it leaves the web server, which can appear to an observer as in-transit tampering.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!