On this page

Atomicorp WAF Rule 381205

Rule Summary

  • Rule ID: 381205
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules - Virtual Just In Time Patch: Curltest Probe
  • Observed CWEs: None documented
  • Revision: 2
  • Rule severity: Critical (2)
  • Request surfaces: Request URI
  • Rule action: deny
  • Logging: log, auditlog

Description

This rules detects if attempt is made to access the curltest web application. This may be an indication of an attack.

Troubleshooting

False Positives

A false positive can occur if you allow access to the curltest web application.

Please do not report false positives in cases where you allow access to this application. The rule is designed to detect attempts to access this web application. If you wish to allow access to this web application, simply disable this rule. If the request was not access the curltest webapplication, please report this as a false positive to our support team.

Tuning Guidance

If you know that this behavior is acceptable for your domain, you can either disable the rule for the server, or you can disable it for the application.

Please see the Tuning the Atomicorp WAF Rules page for basic information.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

No selected related public CVE research notes are currently published.

Documentation Source

  • Original wiki page: WAF 381205
  • Source revision: 2822
  • Source revision date: 2012-10-20