On this page

Atomicorp WAF Rule 330019

Rule Summary

  • Rule ID: 330019
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: Suspicious Web Client Detected (Disable this rule if you wish to allow these clients)
  • Observed CWEs: None documented
  • Revision: 3
  • Rule severity: Error (3)
  • Phase: 2 (request body)
  • Request surfaces: Request headers
  • Rule action: deny
  • HTTP status: 403
  • Logging: log, auditlog

Description

This rule detects clients or libraries that are known to sometimes used by malicious parties to carry out unauthorized, or potentially malicious purposes. These clients are not necessary conducting malicious or unauthorized behavior, but they are know to be used by malicious parties as spamming tools, worms, web site “scrapers”, attack tools and others. Some users prefer to block these clients to prevent malicious activity or excessive use of bandwidth from these clients.

If you wish to allow these clients, just disable this rule.

False Positives

This rule has no known false positives. If you wish to allow these clients, disable this rule.

If you believe this is a false positive, please report this to our security team. Instructions to report false positives are detailed on the Reporting False Positives wiki page.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

No selected related public CVE research notes are currently published.

Documentation Source

  • Original wiki page: WAF 330019
  • Source revision: 1142
  • Source revision date: 2011-01-13