<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS detects HTML SQL Injection attempt (35827) only after WebServer returns 302 on original requ in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/ips-detects-html-sql-injection-attempt-35827-only-after/m-p/295584#M668</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41122"&gt;@Benoit_Malenfant&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Is the traffic running over HTTPS and if so are you performing decryption on the traffic?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 31 Oct 2019 21:45:43 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-10-31T21:45:43Z</dc:date>
    <item>
      <title>IPS detects HTML SQL Injection attempt (35827) only after WebServer returns 302 on original request</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/ips-detects-html-sql-injection-attempt-35827-only-after/m-p/295493#M667</link>
      <description>&lt;P&gt;During an event investigation, noticed the following behavior:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Attacker sends SQL injection request to WebServer (that sits behind a Palo-Alto).&lt;/LI&gt;&lt;LI&gt;WebServer answers with HTTP 302 to redirect to error page (the error page is basically "/error.aspx/[original request from attacker]")&lt;/LI&gt;&lt;LI&gt;Attacker follows the 302&lt;/LI&gt;&lt;LI&gt;IPS blocks request at this point.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I'm wondering why the IPS is not blocking the SQL injection attempt when the original request from the attacker is sent and only blocks it once the attacker tries to follow the 302?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone else noticed the same behavior?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 16:03:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/ips-detects-html-sql-injection-attempt-35827-only-after/m-p/295493#M667</guid>
      <dc:creator>Benoit_Malenfant</dc:creator>
      <dc:date>2019-10-31T16:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: IPS detects HTML SQL Injection attempt (35827) only after WebServer returns 302 on original requ</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/ips-detects-html-sql-injection-attempt-35827-only-after/m-p/295584#M668</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41122"&gt;@Benoit_Malenfant&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Is the traffic running over HTTPS and if so are you performing decryption on the traffic?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 21:45:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/ips-detects-html-sql-injection-attempt-35827-only-after/m-p/295584#M668</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-10-31T21:45:43Z</dc:date>
    </item>
  </channel>
</rss>

