-
-
Notifications
You must be signed in to change notification settings - Fork 402
PL 1 False Positive on Blacklist Keywords from Node-Validator #2060
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
Hi @RubieV, thanks for your report. We will investigate this issue shortly, and will give a solution. |
I remember some heated conversations about This is a great first issue as it's basically copying the existing rule into the Paranoia Level 2 section of the file (remembering to give it a new ruleId and giving it the |
Moved --> keyword from 941180 (PL1) into new stricter sibling rule 941181 (PL2) #2060
Description
For several environments, the PL1 rule
Blacklist Keywords from Node-Validator (941180)
, is triggering on legitimate user's input, especially in customer feedback forms.The rule itself contains good signatures for the detection of actual attacks (i.e.
document.cookie
), however is mixed with the payload-->
, which is causing the common false positives.Audit Logs / Triggered Rule Numbers
Example
Substantiation
Proposal
Splitting this rule from a single PL1 rule into a PL1 and an PL2 rule.
Your Environment
Original Rule
Confirmation
The text was updated successfully, but these errors were encountered: