On this page

Atomicorp WAF Rule 340361

Rule Summary

  • Rule ID: 340361
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: CONNECT method denied
  • Observed CWEs: None documented
  • Revision: 3
  • Rule severity: Critical (2)
  • Phase: 1 (request headers)
  • Rule action: deny
  • HTTP status: 403
  • Logging: log, auditlog

Description

The CONNECT method can be used to connect to arbitrary services and can turn a web server into a proxy server. For example, this method can be used to connec to port 25 on a mail server, turning a web server into an open relay for spamming. Unless you have configured your system to be a proxy, and have setup appropriate access control it is recommended you leave this rule turned on.

False Positives

Can be triggered if the system is a proxy server.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

No selected related public CVE research notes are currently published.

Documentation Source

  • Original wiki page: WAF 340361
  • Source revision: 659
  • Source revision date: 2009-11-25