On this page
Atomicorp WAF Rule 390900
Rule Summary
- Rule ID: 390900
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Possible Unauthorized Download Client - Rapidleech
- Observed CWEs: None documented
- Revision: 12
- Rule severity: Critical (2)
- Phase: 4 (response body)
- Request surfaces: Response body
- Rule action: deny
- HTTP status: 404
- Logging: log, auditlog
Description
This exclusive capability in the Atomicorp ruleset can detect when a client is either trying to advertise or use an a download client that may violate rate limiters or “antileech” defenses. This helps to detect and block these clients or prevent their advertisement.
Troubleshooting
False Positives
There are no known false positives with this rule. Please do not report this as a false positive if you are advertising or using this client. If you wish to allow this behavior, simply disable this rule.
If you have confirmed that this event is does not involve either the use or advertisement of this client and you believe this is a false positive, please report this following the process at the link below:
Tuning Guidance
Please see the Tuning the Atomicorp WAF Rules page for more information if you wish to disable or modify this rule.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
No selected related public CVE research notes are currently published.
Documentation Source
- Original wiki page: WAF 390900
- Source revision: 5063
- Source revision date: 2014-08-29