Skip to content
View in the app

A better way to browse. Learn more.

Gear Crushers

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Enable Apache Struts Protection via F5 ASM module

Featured Replies

Here are the steps that were followed to protect environment from Apache Struts vulnerabilities

Security - app secuirty - attack signatures - attack signature configuration
Enable Staging
Save - Apply Policy

Security - options - app security - attack signatures - attack signatures update
Delivery Mode: Manual
Browse to File
Click Update Signatures

Security - Options - Application Security - Attack Signatures - attack signature set
Create
apache_struts_CVE...
Type: Manual
200004224
200003458
200003470
200004174
200003440
200100310

Security - Application Security - Attack Signatures - Attack Signature List
Filter Details
Search Signature ID (remove from Staging)
200004224
200003458
200003470
200004174
200003440
200100310
Search Containg String (remove from Staging)
sig.java.lang.processbuilder
"/bin" execution attempt (Headers)
Automated client access "curl"
Java Code Injection (java packages) (Header)
Java code injection - java/lang/Process (Header)
Java code injection java.lang.System (Header)
Java code injection ognl.OgnlContext (Header)
APPLY Policy

Security - Application Security - Content Profiles - XML Profiles
Create
Apache_Struts_Profile
Defense Configuration:
Allow DTDs
Tolerate Leading White Space
Create

Security - Application Security - URLs - Allowed URLs
Next to HTTPS click *
Advanced
Header-Based Content Profiles
Request Header Name: Content-Type
Request Header Value: *xml*
Request Body Handling: XML
Click ADD
Click UPDATE

Same thing for HTTP

APPLY Policy

Create an account or sign in to comment

Important Information

By using this site, you agree to our Terms of Use.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.