On this page

Atomicorp WAF Rule 330036

Rule Summary

  • Rule ID: 330036
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: Suspicious User agent detected. Disable this rule if you use indy library.
  • Observed CWEs: None documented
  • Revision: 1
  • Rule severity: Critical (2)
  • Phase: 2 (request body)
  • Request surfaces: Request headers
  • Rule action: deny
  • HTTP status: 403
  • Logging: log, auditlog

Description

This rule detects if the user agent “indy library” is used. This client is known to be used for some malicious activity, either in the creation of bots or the User Agent field is forged. Most commonly it is used with spammers, and less commonly its used by worms. If you use this user agent, then disable this rule.

False Positives

There are no known false positives with this rule. The rule looks at the User-Agent header and if the application identified itself as “indy library” it will trigger.

If you have examined the headers and have identified a case where the agent is not reporting that that is “indy library”, please report this as a false positive. Otherwise, if you use this user agent, disable this rule for your syste,.

Instructions to report false positives are detailed on the Reporting False Positives wiki page.

If you wish to tune this rule yourself, please see the Tuning the Atomicorp WAF Rules page for basic information.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

No selected related public CVE research notes are currently published.

Documentation Source

  • Original wiki page: WAF 330036
  • Source revision: 5143
  • Source revision date: 2014-10-04