On this page
Atomicorp WAF Rule 300282
Rule Summary
- Rule ID: 300282
- Status: Active
- Alert message: Atomicorp.com WAF AntiSpam Rules: Possible Spam: Broken URL posting type - possible spam
- Observed CWEs: None documented
- Revision: 2
- Rule severity: Warning (4)
- Phase: 2 (request body)
- Request surfaces: Request arguments, JSON request data, SOAP request data
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rules detects when a post is made using broken forum, CMS or other user generated URL formats. For example this format:
[url=http://www.example.com]some link[/url]
Is commonly used by many forum and CMS tools. Some spam tools will attempt to post spam urls to a site, but will post broken urls, for example not closing the url, or injecting multiple url= url= variables in a row.
Troubleshooting
False Positives
None.
Tuning Guidance
See the Mod_security page for guidance on tuning this rule.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
No selected related public CVE research notes are currently published.
Documentation Source
- Original wiki page: WAF 300282
- Source revision: 3127
- Source revision date: 2013-01-28