On this page

Atomicorp WAF Rule 390900

Rule Summary

  • Rule ID: 390900
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: Possible Unauthorized Download Client - Rapidleech
  • Observed CWEs: None documented
  • Revision: 12
  • Rule severity: Critical (2)
  • Phase: 4 (response body)
  • Request surfaces: Response body
  • Rule action: deny
  • HTTP status: 404
  • Logging: log, auditlog

Description

This exclusive capability in the Atomicorp ruleset can detect when a client is either trying to advertise or use an a download client that may violate rate limiters or “antileech” defenses. This helps to detect and block these clients or prevent their advertisement.

Troubleshooting

False Positives

There are no known false positives with this rule. Please do not report this as a false positive if you are advertising or using this client. If you wish to allow this behavior, simply disable this rule.

If you have confirmed that this event is does not involve either the use or advertisement of this client and you believe this is a false positive, please report this following the process at the link below:

Tuning Guidance

Please see the Tuning the Atomicorp WAF Rules page for more information if you wish to disable or modify this rule.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

No selected related public CVE research notes are currently published.

Documentation Source

  • Original wiki page: WAF 390900
  • Source revision: 5063
  • Source revision date: 2014-08-29