On this page

Atomicorp WAF Rule 330215

Rule Summary

  • Rule ID: 330215
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: Sosospider - Known abusive bot
  • Observed CWEs: None documented
  • Revision: 2
  • Rule severity: Critical (2)
  • Phase: 2 (request body)
  • Request surfaces: Request headers
  • Rule action: deny
  • HTTP status: 403
  • Logging: log, auditlog

Description

This rule is triggered when the Sosospider attempts to connect to the server. This crawler is known to act in an abusive manner which can result in significant impact to the systems resources, causing server slow downs and is known to not respect the robots.txt file.

Troubleshooting

False Positives

There are no known false positives with this rule. The rule looks at the User-Agent header and if the application identified itself as the sosospider it will trigger.

Tuning Guidance

If you wish to allow connections from this spider, disable the rule. Please see the Tuning the Atomicorp WAF Rules page for more information.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

No selected related public CVE research notes are currently published.

Documentation Source

  • Original wiki page: WAF 330215
  • Source revision: 3839
  • Source revision date: 2013-08-10