On this page

Atomicorp WAF Rule 340069

Rule Summary

  • Rule ID: 340069
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: Web vulnerability scanner
  • Observed CWEs: None documented
  • Revision: 4
  • Rule severity: Critical (2)
  • Phase: 2 (request body)
  • Request surfaces: Request URI
  • Rule action: deny
  • HTTP status: 403
  • Logging: log, auditlog

Description

This rule is triggered when known vulnerability scanner actions are detected. This looks for events that vulnerability scanners do on purpose to identify themselves to the system they are testing.

Troubleshooting

False Positives

There are no known false positives with this rule. The rule looks for the known actions that vulnerability scanners take to specifically identify that they are testing the system, and that do this on purpose so that the operators of the system know that they are being scanned. This is a bit akin to asking the police to check your home for security issues, and upon arriving the police ring your doorbell and tell you they will be starting the assessment. Some vulnerability scanners “announce” themselves, and that is what this rule looks for.

False positives with this rule are essentially unheard of. But if you believe you have one, please follow the process documented in the Reporting_False_Positives procedure.

Tuning Guidance

Please see the Tuning the Atomicorp WAF Rules page for more information.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

No selected related public CVE research notes are currently published.

Documentation Source

  • Original wiki page: WAF 340069
  • Source revision: 3917
  • Source revision date: 2013-09-03