On this page

Atomicorp WAF Rule 300061

Rule Summary

  • Rule ID: 300061
  • Status: Active
  • Alert message: Atomicorp.com WAF AntiSpam Rules: Possible Spam or Restricted content: Pharmacy and/or Drug content detected
  • Observed CWEs: None documented
  • Revision: 25
  • Rule severity: Warning (4)
  • Phase: 2 (request body)
  • Request surfaces: Request arguments, JSON request data, SOAP request data
  • Rule action: deny
  • HTTP status: 403
  • Logging: log, auditlog

Description

This rule detects posts pharmacy and prescription drug content. Some sites restrict this type of content either to prevent spamming of pharmacetucial sites, or for legal reasons. If your site allows this type of content, disable this rule.

The procedure for disabling rules is documented on the follow page: Mod_security#Disable_a_Mod_security_rule_.28or_rules.29_for_all_applications_in_a_single_domain

False Positives

A false positive can occur when sites allow this content. The rules contain a large library of known administrative functions that would need to use this content (such as blocking this content, or adding this content to a website). The rules deliberately do not allow non-administrative users, such as forum or blog thread users to post this type of content. The rules is designed to prevent those types of users from posting this type of content (not admins).

If you know that this action was purely administrative, and not a regular user, please report this as a false positive.

It is not recommended that you disable this rule if you have a false positive. If you believe this is a false positive, please report this to our security team to determine if this is a legitimate case, or if its clever attack on your system. Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.

Tuning Guidance

Please see the Tuning the Atomicorp WAF Rules page for basic tuning guidance.

Similar Rules

WAF_300038

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

No selected related public CVE research notes are currently published.

Documentation Source

  • Original wiki page: WAF 300061
  • Source revision: 2243
  • Source revision date: 2012-03-20