3 votes

For the Firewall rules please add the option of Contains or Does Not Contain. This is helpful because current settings only allow Is or Is Not. There are times when rules are not exact and you want pattern matching. For example on Client User Agent you could use Contains to block any user agent string that starts with Mozilla/4.0 which is usually an attack tool or bad bot (Mozilla/5.0 is legitimate). Another example would be to block nmap, arachni, dirbuster, etc... by user agent string without having to list the whole string that includes the version number. An example is DirBuster-0.12 (http://www.owasp.org/index.php/Category:OWASP_DirBuster_Project). I work on Akamai and Imperva and having Contains options are always helpful.

Suggested by: Mike Upvoted: 27 Sep, '19 Comments: 1


Comments: 1

Add a comment

0 / 1,000

* Your name will be publicly visible

* Your email will be visible only to moderators