On this page
Atomicorp WAF Rule 330072
Rule Summary
- Rule ID: 330072
- Status: Retired
- Alert message: Atomicorp.com WAF Rules: Comment Spammer User Agent (Fake IE)
- Observed CWEs: None documented
Description
This rule detects if a connecting client reports that it is using a “User Agent” that is known to be fake. This particular rule detects clients that claim to be using Internet Explorer, however the reported information is clearly fake.
Attacker and spammers sometimes use fake user-agent strings to either hide the real software they are using, or to hope to fool some web applications into believing a legitimate user is connecting.
False Positives
A false positive can occur if a user’s client software is deliberately creating a fake, and invalid user-agent string. Its important to note that this rule does not trigger if a client uses a valid Internet Explorer version string. This only detects if the reporting information is completely fake, for example, a client that is reporting it is running “Internet Explorer 9999”. There is no version “9999” of Internet Explorer.
It is not recommended that you disable this rule if you have a false positive. If you believe this is a false positive, please report this to our security team to determine if this is a legitimate case, or if its clever attack on your system. Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.
Tuning Guidance
If you know that this behavior is acceptable for your application, you can tune it by following guidance on the Tuning the Atomicorp WAF Rules page for basic information.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
No selected related public CVE research notes are currently published.
Documentation Source
- Original wiki page: WAF 330072
- Source revision: 2216
- Source revision date: 2012-03-04