Difference between revisions of "WAF 340008"

From Atomicorp Wiki
Jump to: navigation, search
 
Line 15: Line 15:
 
This rule is detecting the use of a bogus path.  An example of a bogus path would be:
 
This rule is detecting the use of a bogus path.  An example of a bogus path would be:
  
   /.../somefile
+
   /.../some_file
  
 
There is no such valid path in any operating system.  "..." is an invalid directory.  This would be an indication of a possible attempt to access hidden content on the system, or to create a hidden directory.
 
There is no such valid path in any operating system.  "..." is an invalid directory.  This would be an indication of a possible attempt to access hidden content on the system, or to create a hidden directory.

Latest revision as of 21:11, 25 November 2009

Rule ID

340008

Status

Active rule currently published.

Alert Message

'Atomicorp.com WAF Rules: Bogus Path denied

Description

This rule is detecting the use of a bogus path. An example of a bogus path would be:

 /.../some_file

There is no such valid path in any operating system. "..." is an invalid directory. This would be an indication of a possible attempt to access hidden content on the system, or to create a hidden directory.

False Positives

There are no known valid conditions in which this can occur.

If you believe this to be a a false positive, please report this to our security team to determine if this is a legitimate case, or if its clever attack on your system. Instructions to report false positives are detailed on the Reporting False Positives wiki page.

If you wish to tune this rule yourself, please see the Tuning the Atomicorp WAF Rules page for basic information.

Tuning Recommendations

There are no known valid conditions in which this can occur, therefore it is not recommended that you tune the system to allow this.

Similar Rules

WAF_340007

WAF_340006

Knowledge Base Articles

None.

Outside References

None.

Personal tools