On this page
Atomicorp WAF Rule 303833
Rule Summary
- Rule ID: 303833
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Fake Google Feedfetcher webcrawler
- Observed CWEs: None documented
- Revision: 5
- Rule severity: Critical (2)
- Phase: 1 (request headers)
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This exclusive capability in the Atomicorp ruleset can detect when a client pretends to be a google feedfetcher webcrawler. This is part of googles search engine technology used with feeds (e.g. RSS). This helps to detect and block potential zero day and other suspicious behavior. Attackers have been know to impersonate webcrawlers to trick naive applications that blinding trust webcrawlers. They use this method to gain access that would otherwise be blocked to non-crawlers.
This will not block the real google webcrawler. We do not recommend you disable this rule.
For ASL users, if you enable the option below, ASL will automatically and dynamically whitelist the real google webcrawler from all WAF events:
Troubleshooting
False Positives
There are no known false positives with this rule. Please do not report this as a false positive if you are using a proxy, CDN or other similar service and your web server is not setup per this article:
If you believe this is a false positive, please report this following the process at the link below:
Tuning Guidance
Please see the Tuning the Atomicorp WAF Rules page for more information if you wish to disable or modify this rule.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
No selected related public CVE research notes are currently published.
Documentation Source
- Original wiki page: WAF 303833
- Source revision: 4906
- Source revision date: 2014-06-04