On this page

Atomicorp WAF Rule 350053

Rule Summary

  • Rule ID: 350053
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: Threat Intelligence Match for known Brute Force attacker on Atomicorp Threat Intelligence RBL. See this URL for details http://www.atomicrbl.com (opens in a new tab) (Previous TI-3 Match)
  • Observed CWEs: None documented
  • Revision: 2
  • Rule severity: Error (3)
  • Phase: 2 (request body)
  • Rule action: deny
  • HTTP status: 403
  • Logging: log, auditlog

Description

This rules detects when an IP address connecting to your server is listed on the Atomicorp.com Threat Intelligence database. This means the IP has been repored by other systems running ASL as having attempted to login into services and having failed multiple times. This may indicate the system is being used to attempt to brute force accounts and has been compromised, or this may indicate that there is a misconfigure application on the system that is attempting to log into multiple systems and failing multiple times.

You can lookup details on this IP address at this URL:

This rule can only be triggered if you have enabled the optional MODSEC_00_THREAT ruleset, which is disabled by default.

Troubleshooting

False Positives

If you believe this is a false positive, that is this IP address is not compromised and has not been used recently to attack other systems, please report this to our support desk.

Configuration Notes

This ruleset requires a very fast local DNS server. If you do not have a local and fast DNS server, you should not use these rules. The system will not serve up any webpages until the DNS lookup completes, and if you do not have a fast local DNS server this can result in the false impression that the web server is “slow”. The server is actually not impacted by the rules, the server is simply waiting on the DNS server to respond to a query. So the web server, when using these rules, will only be as fast as the DNS server it is using.

Tuning Guidance

Please see the Tuning the Atomicorp WAF Rules page for basic information.

Additional Information

Similar Rules

WAF_355500

WAF_355501

WAF_355503

WAF_355506

WAF_350051

WAF_350053

WAF_350054

WAF_350055

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

No selected related public CVE research notes are currently published.

Documentation Source

  • Original wiki page: WAF 350053
  • Source revision: 5958
  • Source revision date: 2018-08-28