IPS detects HTML SQL Injection attempt (35827) only after WebServer returns 302 on original request

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

IPS detects HTML SQL Injection attempt (35827) only after WebServer returns 302 on original request

During an event investigation, noticed the following behavior:

 

  1. Attacker sends SQL injection request to WebServer (that sits behind a Palo-Alto).
  2. WebServer answers with HTTP 302 to redirect to error page (the error page is basically "/error.aspx/[original request from attacker]")
  3. Attacker follows the 302
  4. IPS blocks request at this point.

I'm wondering why the IPS is not blocking the SQL injection attempt when the original request from the attacker is sent and only blocks it once the attacker tries to follow the 302?

 

Anyone else noticed the same behavior? 

1 REPLY 1

Cyber Elite
Cyber Elite

@Benoit_Malenfant,

Is the traffic running over HTTPS and if so are you performing decryption on the traffic? 

  • 3503 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!