On this page
Atomicorp WAF Rule 300080
Rule Summary
- Rule ID: 300080
- Status: Active
- Alert message: Atomicorp.com WAF AntiSpam Rules: Free antivirus/spyware Link/Content
- Observed CWEs: None documented
- Revision: 5
- Rule severity: Warning (4)
- Phase: 2 (request body)
- Request surfaces: Request arguments, JSON request data, SOAP request data
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rules detects content about free antivirus, antimalware and anti spyware software. Some websites do not allow this type of content, as it is also used by fake antivirus companies and scammers that advertise free antivirus software that actually contains malware.
Disable this rule if you website allow this type of content.
Troubleshooting
False Positives
A false positive can occur when a website legitimately uses this type of content, or if there is an error in the patterns used to detect this type of spam. The rules contain a large library of known web applications and safe methods for using this content, such as administrative functions, and can detect known safe methods and ignore them. However it is possible for a new or custom application to do this in an unknown manner and incorrectly trigger this rule.
It is not recommended that yo isable this rule if your site does not allow this type content. If your site does allow this type of content, then you will want to disable this rule.
If your site does not allow this type of content, and yo¾lieve this is a false positive (it does not contain this type of content), please report this to our security team. Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.
Tuning Guidance
Please see the Tuning the Atomicorp WAF Rules page for basic information if you wish to tune, or disable this rule.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
No selected related public CVE research notes are currently published.
Documentation Source
- Original wiki page: WAF 300080
- Source revision: 5136
- Source revision date: 2014-09-24