On this page

Atomicorp WAF Rule 377777

Rule Summary

  • Rule ID: 377777
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: Possible Spam Domain: URIBL Match of Submitted Link Domain on urirbl.com blocklist. (Report False Positives to www.uribl.com (opens in a new tab) )
  • Observed CWEs: None documented
  • Revision: 1
  • Rule severity: Critical (2)
  • Phase: 2 (request body)
  • Request surfaces: Request arguments, JSON request data, SOAP request data
  • Rule action: deny
  • Logging: log, auditlog

Description

This rules detects that a domain in a URI is listed on the urirbl.com’s “black” DNS zone as a spam domain.

False Positives

There are no known False Positives for this rule. However, the DNS list itself is run by urirbl.com, and if you have this rule active your system will query that projects DNS lists. The data does not reside on your system, its hosted by the urirbl.com project. Therefore, if a domain is incorrectly returned from their DNS servers as being on their black list, the error lies with the urirbl.com server.

Please report any false positives to the urirbl.com project. Atomicorp does not run this RBL, and therefore can not address false positives with domains on this URI rbl. You can access their website here:

Similar Rules

WAF_350000

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

No selected related public CVE research notes are currently published.

Documentation Source

  • Original wiki page: WAF 377777
  • Source revision: 4413
  • Source revision date: 2014-01-17